3 ms·
That’s not correct at all. Are you confusing it with SameSite or something like that?
by JimDabell 4mo ago
That’s not correct at all. Are you confusing it with SameSite or something like that?
- Izkata 4mo agoI may be wrong about the specific security thing involved, but I know it would have broken ajax requests (probably XMLHTTPRequest, not fetch) to different domains had we not made changes to deal with it. They worked without issues before that.
- JimDabell 4mo agoYou could not make cross-domain Ajax requests at all until CORS came along. There were lots of workarounds people had to invent (e.g. JSONP, Flash shims, proxying, etc.) precisely because this security barrier has been in place since the mid-90s, a couple of decades before CORS came along. The whole point of CORS was to enable cross-domain requests.