Skip to content

Insecure cross site request handling #9

@irusland

Description

@irusland

Server always set header
Access-Control-Allow-Origin: '*' for all preflight OPTIONS requests
this approach seems insecure.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions