Hacker News new | ask | show | jobs
by floatingatoll 1701 days ago
Redirects are fine as long as no container-type things are in play (since those don't necessarily carry the origin's cookies across the boundary), it's embedded cross-domain auth forms in an iframe that can cause a dialog.