Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, a script should be able to set of a naked HTTP request to `othersite.com` without sending along the cookies for `othersite.com`. I don't see how that would allow new vulnerabilities.

Basically, make XMLHttpRequest not use any cookies etc. when making requests to other domains.



Yes without cookies it should be able to, since it can via a proxy. this should be a capability of browsers




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: