3 ms·
Accepted your PR, this is indeed a CORS alternative, not a polyfil. I did think about utilizing CORS headers, however by placing a proxy.html file on your doma
by jpillora 12y ago
Accepted your PR, this is indeed a CORS alternative, not a polyfil.
I did think about utilizing CORS headers, however by placing a proxy.html file on your domain, you can be seen as implicitly allowing cross-domain requests. I've added a simple DSL to the script tag to futher restrict access. To only accept requests from 'foo.master-domain.com', just do:
<script ... master="foo.master-domain.com">
Adding CORS to XDomain is an unnecessary complication, CORS requires modifying the server code, CORS can cause superfluous requests and CORS sucks.
RE: pmxdr: since you don't replace XMLHttpRequest, it doesn't work after dropping it in. Does jQuery's $.ajax magically work? Angular's $http?