3 ms·
But for XHR only POST requests that meet a lot of constraints (defined here https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#Simple_requests https://devel
by pixelperfect 7y ago
But for XHR only POST requests that meet a lot of constraints (defined here https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#Simple_requests https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#Simpl...) will work, right?
Nothing with a Cookie header for example...
- Thorrez 7y agoThat page says that the Cookie header cannot be "manually set". Headers can still be automatically sent, and the browser can automatically send cookies from the cookie jar. So for example this will not send a request with the manually set cookie: r = new XMLHttpRequest(); r.withCredentials = true; r.addEventListener('load', function(e) {console.log('loaded: ', this, e);}); r.addEventListener('error', function(e) {console.log('error: ', this, e);}); r.open('GET', 'https://www.google.com'); r.setRequestHeader('Cookie', 'somecookie=somecookievalue') r.send(); But this will send a request with the automatically set cookies just fine: r = new XMLHttpRequest(); r.withCredentials = true; r.addEventListener('load', function(e) {console.log('loaded: ', this, e);}); r.addEventListener('error', function(e) {console.log('error: ', this, e);}); r.open('GET', 'https://www.google.com'); r.send(); Assuming the user is already logged in to bank.com , the user's cookies will be automatically sent on the request, and the transfer will go through assuming there is no CSRF protection.