4 ms·
> Again, CORS does not protect, the SOP does :-) This is simply false. You are somehow wrongly assuming that only same-origin requests exist or are needed. Thi
by fivea 5y ago
> Again, CORS does not protect, the SOP does :-)
This is simply false. You are somehow wrongly assuming that only same-origin requests exist or are needed. This scenario never existed in the real world beyond the scope of small personal projects.
- feanaro 5y agoTo explain your error a bit less facetiously, the point my sibling is making is that SOP is the default policy, which is maximally restrictive. CORS is a technology used to relax SOP, to make it less restrictive. So it is not CORS that protects, since it restricts nothing, but SOP (potentially relaxed by CORS).
- shukantpal 5y ago> You are somehow wrongly assuming that only same-origin requests exist or are needed. No they are not making that assumption.
- JanSt 5y agoHow am I assuming that? How exactly does CORS add security?