Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Every ad GET is doing a lot of things that violate that edict.


Yes, but if ads do it, that would at worst make the ad server vulnerable, not your server.


You apparently understand less than me. The little I do understand is that CORS is protection for a site's user, not the site.


It's a protection of site's business model.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: