248
SPAs were a mistake
(lemmy.world)
Post funny things about programming here! (Or just rant about your favourite programming language.)
Then again, cookie auth is vulnerable to CSRF. Pick your poison.
Although CSRF protection just adds a minor inconvenience, while there is never a guarantee your code is XSS vulnerability free.