<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Talk%3ATest_Cross_Origin_Resource_Sharing_%28OTG-CLIENT-007%29</id>
		<title>Talk:Test Cross Origin Resource Sharing (OTG-CLIENT-007) - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Talk%3ATest_Cross_Origin_Resource_Sharing_%28OTG-CLIENT-007%29"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;action=history"/>
		<updated>2026-04-29T10:20:07Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247838&amp;oldid=prev</id>
		<title>Collin Sauve at 20:37, 25 February 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247838&amp;oldid=prev"/>
				<updated>2019-02-25T20:37:01Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:37, 25 February 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I've removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I've removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine unless you also allow credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine unless you also allow &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;credentials and the server authenticates using those &lt;/ins&gt;credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;.&amp;#160; As an example an API that authenticates using Bearer Auth does not have any need to concern itself with cross-origin calls since the possession of the bearer token is what matters&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 2 is an XSS problem.&amp;#160; The only thing that that CORS could do here is CORS headers on the '''attacker's''' site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the alleged misconfiguration is on the attacker's site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 2 is an XSS problem.&amp;#160; The only thing that that CORS could do here is CORS headers on the '''attacker's''' site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the alleged misconfiguration is on the attacker's site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Collin Sauve</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247837&amp;oldid=prev</id>
		<title>Collin Sauve at 20:34, 25 February 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247837&amp;oldid=prev"/>
				<updated>2019-02-25T20:34:35Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:34, 25 February 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot; &gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine unless you also allow credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine unless you also allow credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 2 is an XSS problem.&amp;#160; The only that that CORS could do here is CORS headers on the '''attacker's''' site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the alleged misconfiguration is on the attacker's site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 2 is an XSS problem.&amp;#160; The only &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;thing &lt;/ins&gt;that that CORS could do here is CORS headers on the '''attacker's''' site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the alleged misconfiguration is on the attacker's site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Collin Sauve</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247836&amp;oldid=prev</id>
		<title>Collin Sauve at 20:34, 25 February 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247836&amp;oldid=prev"/>
				<updated>2019-02-25T20:34:25Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:34, 25 February 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I've removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I've removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;UNLESS &lt;/del&gt;you also allow credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;unless &lt;/ins&gt;you also allow credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 2 is an XSS problem.&amp;#160; The only that that CORS could do here is CORS headers on the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;ATTACKER&lt;/del&gt;'&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;S &lt;/del&gt;site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;quot;&lt;/del&gt;misconfiguration&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;quot; &lt;/del&gt;is on the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;attackers &lt;/del&gt;site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Example 2 is an XSS problem.&amp;#160; The only that that CORS could do here is CORS headers on the '&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''attacker's''' &lt;/ins&gt;site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;alleged &lt;/ins&gt;misconfiguration is on the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;attacker's &lt;/ins&gt;site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Collin Sauve</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247835&amp;oldid=prev</id>
		<title>Collin Sauve at 20:33, 25 February 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247835&amp;oldid=prev"/>
				<updated>2019-02-25T20:33:27Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:33, 25 February 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I've removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I've removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine UNLESS you also allow credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Example 2 is an XSS problem.&amp;#160; The only that that CORS could do here is CORS headers on the ATTACKER'S site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the &amp;quot;misconfiguration&amp;quot; is on the attackers site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* Example 1 is not an example of an inherently insecure request.&amp;#160; Allowing all origins is perfectly fine UNLESS you also allow credentials.&amp;#160;  If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Example 2 is an XSS problem.&amp;#160; The only that that CORS could do here is CORS headers on the ATTACKER'S site could mitigate that, which is outside of your control.&amp;#160; Just a terrible, terrible example of CORS misconfigurations since the &amp;quot;misconfiguration&amp;quot; is on the attackers site.&amp;#160; Amazing that this example made it into this wiki in the first place.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Collin Sauve</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247834&amp;oldid=prev</id>
		<title>Collin Sauve: Created page with &quot;I've removed the bad &quot;Gray Box&quot; examples as they are BOTH bad: Example 1 is not an example of an inherently insecure request.  Allowing all origins is perfectly fine UNLESS yo...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007)&amp;diff=247834&amp;oldid=prev"/>
				<updated>2019-02-25T20:33:16Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;I&amp;#039;ve removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad: Example 1 is not an example of an inherently insecure request.  Allowing all origins is perfectly fine UNLESS yo...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;I've removed the bad &amp;quot;Gray Box&amp;quot; examples as they are BOTH bad:&lt;br /&gt;
Example 1 is not an example of an inherently insecure request.  Allowing all origins is perfectly fine UNLESS you also allow credentials.   If anyone wants to claim that it is insecure you'll need to justify your reasoning here not just assert it.&lt;br /&gt;
&lt;br /&gt;
Example 2 is an XSS problem.  The only that that CORS could do here is CORS headers on the ATTACKER'S site could mitigate that, which is outside of your control.  Just a terrible, terrible example of CORS misconfigurations since the &amp;quot;misconfiguration&amp;quot; is on the attackers site.  Amazing that this example made it into this wiki in the first place.&lt;br /&gt;
[[User:Collin Sauve|Collin Sauve]] ([[User talk:Collin Sauve|talk]]) 14:33, 25 February 2019 (CST)&lt;/div&gt;</summary>
		<author><name>Collin Sauve</name></author>	</entry>

	</feed>