Hacker News new | ask | show | jobs
by thinkloop 2642 days ago
Disabling CORS would allow you to make straight requests to foreign content from your site and manipulate the responses exactly as though they came from your own servers - no iframe needed. CORS does not disable iframe sandboxing.