A few months ago I watched a bot POST to /admin/videos/delete on a staging box and wipe a test playlist without ever authenticating a form. The request carried a valid session cookie — because the browser attaches cookies to any request to our origin — and my admin panel happily trusted it. That is CSRF in its purest form, and it is embarrassingly...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3657940