2 ms·
To respond to a question in the blog post: >> The motivation is that the <form> element from HTML 4.0 (which predates cross-site fetch() and XMLHttpRequest) ca
by yonran 2y ago
To respond to a question in the blog post:
>> The motivation is that the <form> element from HTML 4.0 (which predates cross-site fetch() and XMLHttpRequest) can submit simple requests to any origin,…
> Question to readers: How is that in line with the SameSite initiative?
I actually added that little paragraph to the MDN CORS article in 2022 (https://github.com/mdn/content/pull/20922 https://github.com/mdn/content/pull/20922) to clarify where the term “simple request” from CORS came from, since previously the article only said that it is not mentioned in the fetch spec. You’re right that the paragraph did not mention the 2019 CSRF prevention in browsers that support or default to SameSite=Lax (https://www.ietf.org/archive/id/draft-ietf-httpbis-rfc6265bis-19.html#strict-lax https://www.ietf.org/archive/id/draft-ietf-httpbis-rfc6265bi...), so cross-site forms with method=POST will not have cookies anymore unless the server created the cookie with SameSite=None.
It is quite confusing that SameSite was added seemingly independently of CORS preflight. I wonder why browser makers didn’t just make all cross-origin POST requests require a preflight request instead of making same-site-flag a field of each cookie.