logoalt Hacker News

mr_toadtoday at 2:19 PM1 replyview on HN

> Isn't that what CSRF protections are for, not CORS?

Without the same origin policy CSRF protections would be trivial to circumvent, since you’d be able to read the CSRF token from any page.


Replies

cyphartoday at 4:56 PM

Sure, but that falls under the "no unauthorised GET data" thing I talked about...?