Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Isn't that what CSRF protections are for, not CORS?

Without the same origin policy CSRF protections would be trivial to circumvent, since you’d be able to read the CSRF token from any page.



Sure, but that falls under the "no unauthorised GET data" thing I talked about...?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: