KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
XMLHttpRequest s require CORS to work cross-domain. Similarly for web fonts, WebGL textures, and a few other things. In general all new APIs seem to have this restriction. Why? It's so easy to circumvent: all it takes is a simple server-side proxy. In other words, server-side code isn't prohibited from doing cross-domain requests; why is client-side code? How does this give any security, to anyone? And it's so inconsistent: I can't XMLHttpRequest , but I can <script src> or <link rel> or <img src> or <iframe> . What does restricting XHR etc. even accomplish?
Tags (comma-separated)
Save Edits
Cancel