Hacker News new | ask | show | jobs
by betenoire 881 days ago
it sounded server side code allow-list the source, so it was probably just doing a string prefix check. the code to make the friend relation doesn't happen in the browser