Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think that everyone is capable of or should be implementing csrf protection or cors handling. While the standard library is an awesome starting point, telling people that it is sufficient is not going to convince them.


I wrote CORS handling in one project, it's like 10-20 lines of code. Very simple and well documented feature.


Good for you but most people don't even know what a preflight request is so I would maintain my position that it is not obvious.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: