Hacker News new | ask | show | jobs
by nelsontky 2042 days ago
Cuz they are supposed to be called by people building various apps, and it does not make sense to limit the source of the network requests
1 comments

Their API allows CORS requests from everywhere, what do they need to "step up"?