anti-csrf-plugin
anti-csrf-plugin copied to clipboard
Double top domains (.co.uk) screws everything up
It'll think that the "main domain" is "co.uk" and thus allow anything to be CSRF'd there. Thanks @fransrosen for pointing this out.
Solvable by testing it using document.domain=x as it won't allow you to traverse up to co.uk.