Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You are right that this article isn't going to enable someone to setup CORS correctly.

It is actually kind of weird that it's in here, because the other things they talk about add more security, but if you don't need CORS and you decide to just add it to your configuration for no reason, you actually now have less security. Especially if you return * for the allowed origin.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: