home
csrf is blocked! Well!
...but the following is successful (note: it's an "in site" execution): Evil/Delete