Open
Description
I asked this in #3 but at the time I wasn't using JSON only API, so I didn't try it out.
Now that I am designing such an API, this question pops up again: it seems JSON only API is not immune from XSRF, you need at least request.type check and possibly more:
http://security.stackexchange.com/questions/10227/csrf-with-json-post