Test CSRF and xss

nothing to see here