hbz / lobid

Linking Open Bibliographic Data
https://lobid.org/
Eclipse Public License 2.0
16 stars 4 forks source link

Prepend JSONP response with empty comment to avoid CSRF #21

Closed fsteeg closed 10 years ago

fsteeg commented 10 years ago

Details: http://miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/

Deployed to staging: http://test.lobid.org/resource?name=Faust&format=full&callback=test