Account email
The POST endpoint trusts the session cookie and does not require an anti-CSRF token.
CURRENT ACCOUNT STATE
maya@example.test
Lab session not started
Test workflow
- Establish the victim session. This simulates Maya already being signed in to ClientPortal.
- Open the attacker site in a new tab. Trigger its single forged request.
- Return here and verify account state. If the server accepted the cross-site request, the value above changes and the proof appears.