Oh crap, it actually works

CSRF