How to check if cross-domain requests are disabled

I keep reading to make ajax requests secure, I need to make sure cross-site requests are disabled. On the server side, how can I disable cross-site requests or check if they are disabled / enabled?

+2
source share
3 answers

Cross site requests are disabled by default ..
fyi: take a look at the same origin policy: http://en.wikipedia.org/wiki/Same_origin_policy

+2
source

Cross domain is always denied due to the same source policy .

Both for your JavaScript creating XHR, and for someone faked, they are the same and impossible to differentiate (although you can definitely make it harder).

+1
source

Maybe someone can open your page in a hyperlink, so please make sure that http referrer is always from your site.

0
source

Source: https://habr.com/ru/post/1338805/


All Articles