“If the request is a GET, HEAD, or OPTIONS, request, the request is valid. (These methods are always safe.)”
GET and HEAD do not require/trigger pre-flight in browsers but should still be validated server-side against CORS rules to ensure no data is leaked, right? 🤔
“If the request is a GET, HEAD, or OPTIONS, request, the request is valid. (These methods are always safe.)”
GET and HEAD do not require/trigger pre-flight in browsers but should still be validated server-side against CORS rules to ensure no data is leaked, right? 🤔