• 0 Posts
  • 11 Comments
Joined 3 months ago
cake
Cake day: June 23rd, 2024

help-circle

  • Unless I’m missing something, the post is plain wrong in some parts. You can’t POST to a Cross-Site API because the browser will send a CORS preflight first before sending the real request. The only way around that are iirc form submits, for that you need csrf protection.

    Also the CORS proxy statement is wrong if I don’t misunderstand their point. They don’t break security because they are obviously not the cookie domain. They’re the proxy domain so the browser will never send cookies to it.

    Anyways, don’t trust the post or me. Just read https://owasp.org/ for web security advice.







  • Agreed. Even going back to sharing stuff via Whatsapp or something like that, they are going to evade control for sure. But when will society be ready to just be honest with kids about what exists and teach them how to safely explore that and give them context? I guess we’d rather have dystopian control than that