
Cross-origin resource sharing
9
MENTIONS
5
EPISODES
5
PODCASTS
Search complete. 9 mentions across 5 episodes found for "Cross-origin resource sharing".
Oct 3, 2026
How WebSockets Power the Real-Time Web
S
21:06speaker_1GUEST
It is a massive vulnerability if you aren't paying attention.
S
21:10speaker_1GUEST
Because the WebSocket upgrade handshake starts as a standard GET request, it completely bypasses the browser's same origin policy and standard CORS rules.
S
21:19speaker_0HOST
Let's unpack those terms for a second.
S
21:21speaker_0HOST
Standard rules usually prevent a website on one domain from reaching into another domain, right? Correct.
Episode 193: Browser Logic Errors & XS-Leaks with Jorian Woltjer
J
61:36JustinHOST
... which is the, the crazy thing.
J
61:36Jorian WoltjerGUEST
The whole CORS is just bypassed.
J
61:39JustinHOST
Yeah, dude.
J
61:39JustinHOST
This is such a beautiful thing, and, uh, I'm, I'm confused as well.
J
63:12JustinHOST
in Chromium.
J
63:12Jorian WoltjerGUEST
And so the, to continue the story, so the, we have this DNS rebinding technique that, that works, but, uh, over the past year they have actually started fixing this, uh, with a feature called Local Network Access, LNA, uh, that will...
J
63:30Jorian WoltjerGUEST
It's, it's kind of a secondary layer of CORS, where even if you fetch a same UR- same origin URL, it'll still try and, uh, check if the IP that's behind it is the same, like, localness, uh, of the one that's requesting it.
J
63:49Jorian WoltjerGUEST
So in our case, we have the public attacker.com-
“Encoded Coordination on the Open Web” by ethanelasky, Can Küçükkurt, frank nakasako, David Africa
T
5:15Type Three AudioNARRATOR
Notably, some of these websites help agents circumvent existing control measures.
T
5:20Type Three AudioNARRATOR
CORS proxies allow agents to circumvent blocked URLs.
T
5:25Type Three AudioNARRATOR
Link shorteners allow agents to cache questions and answers for future models, and jQuery or JSON query splices make this problem worse.
T
5:34Type Three AudioNARRATOR
Get-to-post converters allow models to make writes much more easily.
9. Sessions and the Interactive Loop (Steering Claude Code in the Terminal)
S
31:37speaker_1HOST
Go into the Python backend directory.
S
31:39speaker_1HOST
Check the CORS configuration headers.
S
31:42speaker_1HOST
Run a test request and see if it is rejecting our local frontend URL.
S
31:46speaker_0HOST
And what happens in my terminal window?
S
33:03speaker_0HOST
And what might it say?
S
33:04speaker_1HOST
It might say, I checked the Python backend.
S
33:05speaker_1HOST
The CORS headers are perfectly fine.
S
33:08speaker_1HOST
The issue's not here.
P
Unknown podcast
Sound Stock and API Integration: Turning an Audio Library Into Creative Infrastructure
Sep 8 · 2 Mentions
S
6:22speaker_1UNKNOWN
The backend can bump an asset's version number and issue new URLs to ensure clients don't unknowingly use a revoked file.
S
6:30speaker_1UNKNOWN
Another nuance is cross-origin resource sharing, CORS.
S
6:34speaker_1UNKNOWN
Browser-based web apps need the correct CORS headers so that audio files can be loaded into web audio contexts without headaches.
S
6:42speaker_1UNKNOWN
In fact, with Web Audio API, you could stream a preview directly in the browser, apply an instant effect, and give users immediate feedback about how that clip would sound when layered with their project.
S
6:55speaker_1UNKNOWN
When thinking of authentication again, token revocation is critical if a user subscription lapses or they violate licensing terms.