8 ms·
Do CloudFlare Workers require external HTTP endpoints to have CORS headers like Javascript within webpages need?
by forcer 9y ago
Do CloudFlare Workers require external HTTP endpoints to have CORS headers like Javascript within webpages need?
- deleted 9y ago[deleted]
- kentonv 9y agoNo. CORS is designed to protect two things: - The user's cookies for other origins, which the browser will normally send on any request to those origins. - Behind-the-firewall servers that might be accessible from the user's browser but not from the public internet. Neither of these things apply to Workers: a Worker obviously has no access to the browser's cookie jar, nor does it have the ability to see behind-the-firewall services since it's not behind-the-firewall. CORS does NOT protect against DDoS: Typically, CORS does not prevent you from sending requests; it prevents you from seeing the content of the responses. Any web site in a browser can use an <img> tag or submit an invisible <form> to cause a cross-origin request, CORS or not -- but it can't read what comes back. So, Cloudflare Workers do not enforce CORS. We've implemented different measures specifically to mitigate DDoS.