3 ms·
Routing all your x-domain requests through an unknown third part via vanilla HTTP? What could possibly go wrong?
by Joe8Bit 13y ago
Routing all your x-domain requests through an unknown third part via vanilla HTTP? What could possibly go wrong?
- odedgolan 13y agoIt's just your cross-origin traffic, which is not possible without this library, everything else will behave exactly the same.
- Joe8Bit 13y agoAnd whoever is running this proxy will _promise_ not to log any sensitive information (API keys not the least) or otherwise use/modify the response for their own ends? Not to mention that the API endpoint is HTTP only, meaning everything is broadcast in the clear. Also, cross origin requests are perfectly possible without this library, it's precisely why we use JSONP and CORS. When it comes to security, this library is a collection of anti-patterns. As well as the JS anti-pattern of not overwriting native objects, such as XMLHttpRequest in this context.