logoalt Hacker News

tptacektoday at 5:55 AM1 replyview on HN

Sure it is. The same-origin rule that holds the whole web security model together is entirely a property of browser behavior.


Replies

louiskottmanntoday at 6:10 AM

That's indeed a good example of prior full trusting of the browser by the server.