ionic-team / ionic-team/ionic-docs

CORS headers security implications should be more specific

未关闭
#2,255 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
triage
主要语言
MDX
星标
621
派生
3.2k
平均合并
1 天 2 小时
30 天内合并 PR
86

描述

**URL**
https://ionicframework.com/docs/troubleshooting/cors#a-enabling-cors-in-a-server-you-control

**What is missing or inaccurate about the content on this page?**
The docs state, "_Allowing any origin with Access-Control-Allow-Origin: * is guaranteed to work in all scenarios but may have security implications — like some CSRF attacks — depending on how the server controls access to resources and use sessions and cookies._".

And that is the only word on the security implications of setting CORS headers. I think the docs need to be more specific and take a stance on whether adding the Access-Control-Allow-Origin header set to http://localhost (or whatever the protocol and hostname is), is safe/unsafe.

This is my interpretation.... If the content the server is serving is not sensitive then it is safe to add the headers. Otherwise, I would not want to add the headers and the native http plugin should be used. This is because a malicious site could be running at localhost in the browser, opening up CSRF attacks.

I think being more specific and transparent here is the best approach and will improve security.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。