logoalt Hacker News

masklinntoday at 11:32 AM1 replyview on HN

That’s… not what cors does? CORS will only block browser-mediated “non-simple” requests, they don’t prevent other systems from accessing it as long as they don’t use a browser (or disable CORS in a headless browser).


Replies

rnotarotoday at 12:15 PM

I'm pretty sure they understand that since they wrote that the resources will need to be proxied.

They just want to prevent hotlinking/leeching.

show 1 reply