I suspect this is going to help against some CSRF as well?
The jar is the key new thing, not the emptying.
I suspect this is going to help against some CSRF as well?