Hacker News new | ask | show | jobs
by xg15 37 days ago
Yes, but if ads do it, that would at worst make the ad server vulnerable, not your server.
1 comments

You apparently understand less than me. The little I do understand is that CORS is protection for a site's user, not the site.
It's a protection of site's business model.