Fixed
Details
Details
Assignee
Benjamin Reed
Benjamin ReedReporter
Benjamin Reed
Benjamin ReedComponents
Fix versions
Affects versions
Priority
PagerDuty
PagerDuty
Created March 30, 2015 at 4:47 PM
Updated March 30, 2015 at 8:55 PM
Resolved March 30, 2015 at 4:56 PM
CORS is not necessary for ReST access by the mobile client, it should only be enabled by site administrators who know what they're doing. Right now it's enabled in all cases, but it could expose us to various cross-site-scripting attacks.