Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Cross-origin resource sharing

Cross-origin resource sharing

Dmitry Zhlobo

July 02, 2015
Tweet

More Decks by Dmitry Zhlobo

Other Decks in Programming

Transcript

  1. XSS

  2. CORS • Request: • Origin • Access-Control-Request-Method • Access-Control-Request-Headers •

    Response: • Access-Control-Allow-Origin • Access-Control-Allow-Credentials • Access-Control-Expose-Headers • Access-Control-Max-Age • Access-Control-Allow-Methods • Access-Control-Allow-Headers