Hacker News new | ask | show | jobs
by Sir_Cmpwn 3965 days ago
Stop using JSONP, please! Instead, just support CORS.
1 comments

CORS will not protect you against CSRF - in fact, if you don't apply it with caution it will open you up to CSRF attacks.
Sorry, I wasn't necessarily saying that CORS will save you, but more suggesting that there's no reason to use JSONP.