Security implications of adding all domains to CORS (Access-Control-Allow-Origin: *)
Cross-Site Request Forgery attacks are far and away the primary concern that Access-Control-Allow-Origin addresses. Ryan is certainly correct regarding content retrieval. However, on the subject of making the request there is more to say here. Many web sites now provide RESTful web services that expose a wide range of features that may involve making significant … Read more