Skip to main content
Cross-origin resource sharing

Cross-origin resource sharing

Search complete. 9 mentions across 5 episodes found for "Cross-origin resource sharing".

Oct 3, 2026

speaker_1GUEST
21:06
It is a massive vulnerability if you aren't paying attention.
speaker_1GUEST
21:10
Because the WebSocket upgrade handshake starts as a standard GET request, it completely bypasses the browser's same origin policy and standard CORS rules.
speaker_0HOST
21:19
Let's unpack those terms for a second.
speaker_0HOST
21:21
Standard rules usually prevent a website on one domain from reaching into another domain, right? Correct.
JustinHOST
61:36
... which is the, the crazy thing.
Jorian WoltjerGUEST
61:36
The whole CORS is just bypassed.
JustinHOST
61:39
Yeah, dude.
JustinHOST
61:39
This is such a beautiful thing, and, uh, I'm, I'm confused as well.
JustinHOST
63:12
in Chromium.
Jorian WoltjerGUEST
63:12
And so the, to continue the story, so the, we have this DNS rebinding technique that, that works, but, uh, over the past year they have actually started fixing this, uh, with a feature called Local Network Access, LNA, uh, that will...
Jorian WoltjerGUEST
63:30
It's, it's kind of a secondary layer of CORS, where even if you fetch a same UR- same origin URL, it'll still try and, uh, check if the IP that's behind it is the same, like, localness, uh, of the one that's requesting it.
Jorian WoltjerGUEST
63:49
So in our case, we have the public attacker.com-
Type Three AudioNARRATOR
5:15
Notably, some of these websites help agents circumvent existing control measures.
Type Three AudioNARRATOR
5:20
CORS proxies allow agents to circumvent blocked URLs.
Type Three AudioNARRATOR
5:25
Link shorteners allow agents to cache questions and answers for future models, and jQuery or JSON query splices make this problem worse.
Type Three AudioNARRATOR
5:34
Get-to-post converters allow models to make writes much more easily.
speaker_1HOST
31:37
Go into the Python backend directory.
speaker_1HOST
31:39
Check the CORS configuration headers.
speaker_1HOST
31:42
Run a test request and see if it is rejecting our local frontend URL.
speaker_0HOST
31:46
And what happens in my terminal window?
speaker_0HOST
33:03
And what might it say?
speaker_1HOST
33:04
It might say, I checked the Python backend.
speaker_1HOST
33:05
The CORS headers are perfectly fine.
speaker_1HOST
33:08
The issue's not here.

Unknown podcast

Sound Stock and API Integration: Turning an Audio Library Into Creative Infrastructure

Sep 8 · 2 Mentions

speaker_1UNKNOWN
6:22
The backend can bump an asset's version number and issue new URLs to ensure clients don't unknowingly use a revoked file.
speaker_1UNKNOWN
6:30
Another nuance is cross-origin resource sharing, CORS.
speaker_1UNKNOWN
6:34
Browser-based web apps need the correct CORS headers so that audio files can be loaded into web audio contexts without headaches.
speaker_1UNKNOWN
6:42
In fact, with Web Audio API, you could stream a preview directly in the browser, apply an instant effect, and give users immediate feedback about how that clip would sound when layered with their project.
speaker_1UNKNOWN
6:55
When thinking of authentication again, token revocation is critical if a user subscription lapses or they violate licensing terms.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.