Let's imagine our target is a social media site: https://socialapp.example.com.
You browse the application and look for actions that change the state of your account or data and only require a single click (no text input, drag-and-drop, etc.).
Prime candidates on socialapp.example.com:
- Profile Actions: