something I'm struggling to understand about browser security is why you can send cross-origin POST requests with the user's cookies with a form, but the exact same fetch() call won't include the cookies

(I mean it's clear why we would NOT want to include the cookies, but it feels weird that it's allowed in one context but not in another)

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.jvns.ca/users/b0rk/statuses/116019667869010042 on your instance and quote it. (Note that quoting is not supported in Mastodon.)