Earlier quoted context omitted.
I know, I am an engineer and I obviously let bugs pass too. But this is a little too obvious to me, to check if the user is allowed to remove this url. Maybe I am neurotic? :)
I can see having this pass by a reviewer or two. They look and see all of this: - There are permission checks - The user has to be logged in to GWT - The user has to have access to this page - The user has to be the owner of the siteUrl After all those permission checks, it might appear that everything was covered. It's just one little omission, verifying that the urlt parameter corresponds to a page within the siteU…
[1] http://consumerist.com/2011/06/how-hackers-stole-200000-citi...