Hacker News new | ask | show | jobs
by eurleif 5192 days ago
You shouldn't be able to get the token from another domain, regardless of how long it lasts. How are you able to?
1 comments

Im getting it on the same domain, but the request can be sent from any domain, as long as the user is logged in.