3 ms·
Another thing to note about custom headers is that when used in an XHR (eg: X-Requested-With), they will force a preflight request (with the OPTIONS method). If
by bluesmoon 6y ago
Another thing to note about custom headers is that when used in an XHR (eg: X-Requested-With), they will force a preflight request (with the OPTIONS method). If your webserver isn't configured to handle OPTIONS and return the correct CORS headers, that will effectively break clients.
Best to just never use custom headers.
I've written more about this here: https://developer.akamai.com/blog/2015/08/17/solving-options-performance-issue-spas https://developer.akamai.com/blog/2015/08/17/solving-options...
- pimterry 6y agoYep, you've got to be careful with browser HTTP requests! Conveniently on this very same site I built a CORS tool that knows all those rules and can tell you how they work for every case: https://httptoolkit.tech/will-it-cors/ https://httptoolkit.tech/will-it-cors/
- airza 6y agoI see this a lot as an anti CSRF technique in AJAX based SPAs.
- bluesmoon 6y agoyeah, those techniques predate CORS, but even back then, you'd typically add your anti-csrf token to the payload rather than the header. CSRF is application level logic rather than protocol level.
- uuidgen 6y ago> they will force a preflight request That's why they're so great. use a custom header and never worry about CSRF issues. Use custom header and be sure that if request comes from the browser it was made by legitimate code from your origin.