|
|
|
|
|
by stephbook
38 days ago
|
|
I still don't understand the threat model and, obviously, it's not explained here either. I log in to social.net. I click on scam.org and change sites. I'm on scam.org and it triggers a request to social.net/friends. No cookies are sent, no JWT. I'm not logged in and get a "Needs login" HTTP error. Nothing bad happens. I thought that's how it works without CORS already. |
|
https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Coo...