PaulDotCom mailing list archives

Re: Security of CORS, Would you trust it?


From: Pat <nutjob.ie () gmail com>
Date: Thu, 10 May 2012 15:30:17 +1000

Hi Sub,

I have yet to see it in use by a developer. Its has to be a
very specific scenario to actually use it. Most developers are still facing
the older browser issues and any project I have been involved in has always
been trying to degrade functionality gracefully for older browsers.

So from a protocol standpoint it looks very well thought out around
permissions and sending cookies and credentials. Unfortunately without
seeing some real implementations its tough to answer questions.

If your looking for a starting point some Google hacking may find you some
real world sites using this.

A quick Google hints a foxycart as something i would poke at first.

Sorry to be of no help.



On Thu, May 10, 2012 at 12:40 PM, subzer0girl <subzer0girl () gmail com> wrote:

Anyone have an opinion on the Security of CORS ?  Would you trust it as
your only security mechanism ?



Sub

_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

Current thread: