After login in on user.databox.me any page the user subsequently visits has full access to the user's data and can also add data to the user's LDPCs. Steps to reproduce: - go to https://beta.databox.me/ and log in as <code>https://beta.databox.me/profile/card#me, the password is `tester.` - Access https://retog.github.io/databox-cors-issue/ Expected results: - https://retog.github.io/databox-cors-issue/ fails to create a resource on https://beta.databox.me/ Actual results - https://retog.github.io/databox-cors-issue/ successfully creates a resource on https://beta.databox.me/