Hacker News new | ask | show | jobs
by simonw 3965 days ago
CORS will not protect you against CSRF - in fact, if you don't apply it with caution it will open you up to CSRF attacks.
1 comments

Sorry, I wasn't necessarily saying that CORS will save you, but more suggesting that there's no reason to use JSONP.