logoalt Hacker News

Sophiratoday at 11:40 AM1 replyview on HN

That's not quite correct. POST requests with certain Content-Type headers, such as text/plain or multipart/form-data, will still be allowed without any kind of preflight. If the web application doesn't check the Content-Type header strictly, then you've got a problem.


Replies

stymaartoday at 12:12 PM

You're right, I forgot that form requests bypass the preflight.