Hacker News new | ask | show | jobs
by Beltiras 38 days ago
Every ad GET is doing a lot of things that violate that edict.
1 comments

Yes, but if ads do it, that would at worst make the ad server vulnerable, not your server.
You apparently understand less than me. The little I do understand is that CORS is protection for a site's user, not the site.
It's a protection of site's business model.