_lhermann’s avatar_lhermann’s Twitter Archive—№ 5,821

  1. TIL: The @PaddleHQ API doesn't set proper CORS headers. Instead, their JS SDK uses JSONP instead which introduces a potential security vulnerability 🤨