Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is controlled on browser level and most (all?) browsers implement this. Origin can be faked by just using anything that can make a http request, like curl. It exists to protect users not the server.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: