Wouldn't the root cause be allowing GET requests to perform destructive actions?
1: disabling cookies bypasses security checks
2: a GET request is not side-effect free
The root cause is the combination of both issues.
Wouldn't the root cause be allowing GET requests to perform destructive actions?