Why should font files comply with CORS rules but no image?

When requesting a cross-domain font file, you must ensure that the domain request is allowed to access the font file using CORS headers:

  • Access-Control-Allow-Origin
  • Access-Control-Allow-Credentials

However, this is not required when requesting images, either for img elements or background-image .

Why do these file types have different security?

+5
source share
1 answer

I tried to find a good answer myself several months ago. I saw discussions about this and a kind of rfc , but none if the reasons convinced me.

I think this is one of the things that just needs to be accepted; -)

0
source

Source: https://habr.com/ru/post/1234002/


All Articles