logoalt Hacker News

bastawhizyesterday at 7:45 PM2 repliesview on HN

I think cors can prevent that. You can't make a cross origin request from an origin that isn't allowlisted


Replies

15155yesterday at 9:45 PM

Timing attack on the preflight.

inetknghtyesterday at 9:29 PM

You really think a server-controlled CORS list will protect you from a client-side configuration issue?