How does Google get around cross-site font protection in Firefox with its new Webfonts service?

Google offers websites - http://code.google.com/webfonts

They work in Firefox, but FF has a security policy to stop the use of fonts between sites - http://hacks.mozilla.org/2009/06/beautiful-fonts-with-font-face/ (cross-site search Using a font.

Can anyone guess how they do it? Do they use "access control headers"? Is there any way to check this?

And are there any security issues when adding access control headers?

Thanks in advance.

+4
source share
1 answer

Yes, they use access control headers. You can use Live HTTP Headers to check this:

+3
source

Source: https://habr.com/ru/post/1334606/


All Articles