![]() Cross-origin requests initiated by embedded images and forms actually bring cookies by default. Though it is incorrect to say that all cross-origin requests do not bring credentials by default. |
||
---|---|---|
.. | ||
1-do-we-need-origin | ||
article.md | ||
cors-gmail-messages.svg | ||
xhr-another-domain.svg | ||
xhr-preflight.svg |