snisarenko a day ago

Just something to note.

Websocket connections don't enforce CORS. So that's another alternative - host all of you APIs via websockets.

trick-or-treat a day ago

This feels like a bad idea, there's a reason why we have CORS.

bill-cupid a day ago

forget @trick-or-treat, I love it.

  • TurdF3rguson a day ago

    What happens when his users expose secrets with this thing and an attacker runs up a huge api bill? Pull the plug on this OP.

    • trick-or-treat 2 hours ago

      FaaS - Footgun as a Service, I hope he listens to you and takes it down. The liability on his end is potentialy catastrophic.