Hacker News
new
past
comments
ask
show
jobs
points
by
gray_-_wolf
2 hours ago
|
comments
by
bastawhiz
2 hours ago
|
[-]
I think cors can prevent that. You can't make a cross origin request from an origin that isn't allowlisted
reply
by
15155
23 minutes ago
|
parent
|
next
[-]
Timing attack on the preflight.
reply
by
inetknght
39 minutes ago
|
parent
|
prev
|
[-]
You really think a server-controlled CORS list will protect you from a client-side configuration issue?
reply