3 ms·
imho CORS is poorly designed mechanism, you should be able to flag api.domain.com as a safe place, making a single cors request at start of user interaction wit
by vfistri2 5y ago
imho CORS is poorly designed mechanism, you should be able to flag api.domain.com as a safe place, making a single cors request at start of user interaction with your app.
Also some sort of caching should be more than welcome.
On a side note at previous company I've worked at, speed was critical, so we were forced to do same tactic, use /api instead of api.domain.com which resulted in huge improvements :)
- chrisoverzero 5y ago> Also some sort of caching should be more than welcome. I have good news: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Max-Age https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Ac...