wynd — 4/25/2022, 9:04:20 PM

@jeffalo pls allow any origin to use the api (cors)

♥ 2 ↩ 0 💬 8 comments

comments

lily:

bad idea

4/26/2022, 10:34:59 AM
wynd:

Why, you can already access it several ways

4/26/2022, 11:00:14 AM
lily:

security issue

4/26/2022, 11:01:32 AM
wynd:

In what way

4/26/2022, 11:01:49 AM
lily:

if you’re logged in a malicious site could post as you for example

4/26/2022, 11:13:53 AM
wynd:

You still send auth with requests lil

4/26/2022, 11:16:54 AM
lily:

@jeffalo pls help me to explain

4/26/2022, 11:18:28 AM
wynd:

Are you able to get cookies from the request?

4/26/2022, 1:49:04 PM