3 ms·
> It looks like this is possible because there is not an explicit 'access-control-allow-origin' header set on facebook CORS has nothing to do with it, actually
by mathias 10y ago
> It looks like this is possible because there is not an explicit 'access-control-allow-origin' header set on facebook
CORS has nothing to do with it, actually. This is where the strength of the attack lies.