the answers to "what makes CORS hard?" here are so interesting, so far I'm getting

1) The browser's same-origin policy is very counterintuitive
2) Browser network tools do (I think) have all the info you need to debug, but navigating the Network tab is not easy if you're not used to it
3) Sometimes you need to coordinate with many people to set the correct headers
4) Setting up CORS headers to allow multiple domains (like a.com, b.com, c.com) is annoying

(1/?)

social.jvns.ca/@b0rk/116008592

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.jvns.ca/users/b0rk/statuses/116014050751611822 on your instance and quote it. (Note that quoting is not supported in Mastodon.)