Chrome adding Origin header to same-origin request

后端 未结 2 1565
我寻月下人不归
我寻月下人不归 2020-12-08 16:30

We\'re POSTing an AJAX request to a server running locally, i.e.

xhr.open(\"POST\", \"http://localhost:9000/context/request\");
xhr.addHeader(someCustomHeade         


        
2条回答
  •  悲&欢浪女
    2020-12-08 16:44

    According to RFC 6454 - The Web Origin Concept - the presence of Origin is actually legal for any HTTP request, including same-origin requests:

    http://tools.ietf.org/html/rfc6454#section-7.3

    "The user agent MAY include an Origin header field in any HTTP request."

提交回复
热议问题