[Bug 19236] Enable CORS on entire site

https://www.w3.org/Bugs/Public/show_bug.cgi?id=19236

--- Comment #3 from Eric Bidelman <ericbidelman@chromium.org> 2012-10-03 01:37:28 UTC ---
There's info on security here:
http://code.google.com/p/html5security/wiki/CrossOriginRequestSecurity

...there can be a perf overhead with the preflight request, but that it
minimal.

Is it possible to open it up to only /wiki/tutorial pages for starters?

Also, if we go the route of whitelisting domains, how can folks add/suggest new
ones?

-- 
Configure bugmail: https://www.w3.org/Bugs/Public/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug.

Received on Wednesday, 3 October 2012 01:37:29 UTC