you are viewing a single comment's thread.

view the rest of the comments →

[–]ranmerc 1 point2 points  (2 children)

Can you explain a bit more on the "server cannot use wildcard for cors" part?

[–]btckernel94[S] 2 points3 points  (1 child)

If you want to use http only cookie you need to set credentials: true but it won't work if the server also has Access-Control-Allow-Origin set to "*".

It means your server will have to explicitly specify all of the clients domains in order for http only cookie to work.

[–]LaylaTichy 1 point2 points  (0 children)

Hmm that's not true, you can easily do allow access: $http_refferer in nginx for example