3 ms·
If CORS is supposed to solve the problem of credentials being sent to third-party sites without the user's knowledge, I don't understand why the solution wasn't
by rogual 5y ago
If CORS is supposed to solve the problem of credentials being sent to third-party sites without the user's knowledge, I don't understand why the solution wasn't just to not send the credentials.
- jaffathecake 5y agoThat isn't all it's supposed to solve. Give the article a read, these points are specifically addressed :)
- rogual 5y agoEnlightening, thanks! I had thought maybe a site could in theory use your IP or even just your ability to connect to figure out who it thinks you are, but didn't know this was so common.