Hacker News new | ask | show | jobs
by lol768 2547 days ago
SOP isn't relevant here - it relates generally to _reading_ content from another origin.

What is relevant here is whether the cookies are SameSite and/or whether a token is required.