Skip to content

Minor: Should Delegation File Need Access-Control-Allow-Origin for Given Site to Load? #1030

@thegreatfatzby

Description

@thegreatfatzby

Just upfront, you've got way bigger fish to fry, this isn't blocking anything, and I'm guessing this is just a basic web thing that can't or shouldn't be bypassed...but do want to ask.

It seems that the IG delegation file won't load if Access-Control-Allow-Origin isn't set to allow the calling origin, as a CORS denial shows up in issues (you can see the example here (working on getting the instance a bit more stable :) ) ).

Since the delegation file is there for the browser to learn about what the application wants to allow, and if a result is returned presumably the application returned that intentionally, why not auto-accept the file's results regardless of that header?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions