This should really be a post. If you’re worried about no csrf – a get request is as unsafe, but without communicating that side effects might happen.
True, but it also means you have no way to invalidate this authentication. It stays valid until it expired by whatever static means of expiration you’re using.


















