Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It depends. GET requests are assumed not to have side effects, so often don't have a preflight request (although there are cases where it does). But of course, not all sites follow those semantics, and it wouldn't surprise me if printer or router firmware used GETs to do something dangerous.

Also, form submission famously doesn't require CORS.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: