logoalt Hacker News

StrauXXtoday at 8:25 AM2 repliesview on HN

No, it's exactly the other way around. The SOP protects you from these security issues. CORS is a feature that can be used to loosen up the SOP, to allow more complex inter-application behaviour.


Replies

himata4113today at 8:47 AM

ah right, my own brain got jumbled from reading all the comments forgetting that cors: '*' is not the default.

flux3125today at 10:02 AM

And now he's part of the confusing comment section lol

show 1 reply