3 ms·
The single-value constraint seems like a feature rather than a bug; if you included your full list of whitelisted domains every time, not only would your HTTP h
by jonstaab 7y ago
The single-value constraint seems like a feature rather than a bug; if you included your full list of whitelisted domains every time, not only would your HTTP header size be unnecessarily heavy, but you'd be leaking private details about who else is using your service. This isn't an inherent problem, but it could give an attacker some ideas of who to target.
- politician 7y agoMaybe, but the CORS spec says otherwise. https://www.w3.org/TR/cors/#access-control-allow-origin-response-header https://www.w3.org/TR/cors/#access-control-allow-origin-resp... See the note.
- jonstaab 7y agoInteresting that the spec disagrees with the implementation. Maybe the multi-origin leakage was filed as a bug somewhere and fixed post-spec?