vendredi 10 août 2018

In which scenarios will Chrome not send your Request after a successful OPTIONS response?

So this question is two-fold, for simplicity sake lets assume we want to send a cross domain POST, from domain xyz.com to domain abc.com

In this case the Host header will be "abc.com" and the Origin header is "xyz.com".

1) In which scenarios will Chrome send the OPTIONS request before sending the POST? is it simply Host != Origin ?

2) Assuming the OPTIONS request/response is successful, then the OPTIONS response will have certain headers, which headers need to be present in order for Chrome to send the POST? or if that answer is too long, which headers in the successful OPTIONS response would make chrome NOT send the POST request?

Aucun commentaire:

Enregistrer un commentaire