2 ms·
I'm not 100% on this, but doesn't disabling CORS essentially re-introduce CSRF?
by cwilby 5y ago
I'm not 100% on this, but doesn't disabling CORS essentially re-introduce CSRF?
- cwilby 5y agoTheory is that an attacker can bypass CSRF protections when CORS is disabled by making an extra GET request to parse the CSRF token which is then provided in the next request.
- cwilby 5y agoThen again, I suppose a dedicated attacker can just bypass CORS.
- tasn 5y agoThey are bot disabling CORS, they are just proxying the request throigh the same origin so that for their web app they won't have CORS requests.
- JimDabell 5y agoI think you misunderstand what CORS is. Are you under the impression CORS is a way of blocking requests? It’s the other way around. Browsers prevent most types of requests that go from one hostname/port/protocol to another by default. CORS is a way for a server to tell browsers to relax these restrictions in some way. If you disable CORS, all that means is that the default browser behaviour applies, which means that more types of requests are prevented.
- cwilby 5y agoThanks for helping to clarify!