Hacker News new | ask | show | jobs
by leeoniya 3184 days ago
the implication of same-origin would affect all requests made from the client. you can serve malicious js from the server all day long but it would be restricted to only talking back to that same server.