sarajw,
@sarajw@front-end.social avatar
amxmln,
@amxmln@mastodon.design avatar

@sarajw this does mean any credentials pass through Netlify as well though, right? So it might have some security implications. 🤔

sarajw,
@sarajw@front-end.social avatar

@amxmln well possibly. I'm not making comment on doing anything that requires any auth - I'm only using it to pull in a bunch of RSS feeds, to display the latest posts from various blogs on one page.

hey,
@hey@nowicki.io avatar

@amxmln @sarajw what security implications? CORS is about preventing browsers of sending cookies to third party domains so the host can’t exploit it. Here browser thinks it’s same domain so only same domain cookies are being passed.

amxmln,
@amxmln@mastodon.design avatar

@hey @sarajw Well, it’s a proxy that circumvents CORS because it’s no longer a browser making the request, but a server, that’s the whole point.

I might have something wrong here, but what I was referring to was that everything passed along in the request, such as auth tokens, API keys, etc. would run through Netlify’s servers to reach the destination. As would the response.

hey,
@hey@nowicki.io avatar

@amxmln @sarajw also unsure if in this case nocors mode of fetch would do the job as well. In this mode fetch ignores CORS while also refuses to send any credentials to the other domain.

sarajw,
@sarajw@front-end.social avatar

@hey @amxmln oh it might do. I didn't know that was a thing...

hazelweakly,
@hazelweakly@hachyderm.io avatar

@sarajw ooh I'm gonna see if I can do some absolutely disgusting crimes with this :D

sarajw,
@sarajw@front-end.social avatar

@hazelweakly oh no lol but also colour me intrigued

murtuzaalisurti,
@murtuzaalisurti@mastodon.social avatar

@sarajw I got to know about this when I first deployed a react app on netlify, it was throwing a 404 for anything other than the home page — then it clicked to me that an SPA is a single page so let's redirect all calls to index.html and it worked — but it cost me a whole day to figure that out. This post https://syntackle.live/blog/deploying-react-app-to-netlify-XZ_dWXAd/ was born as a result :)

sarajw,
@sarajw@front-end.social avatar

@murtuzaalisurti ahahaa that's a good point!

janl,
@janl@narrativ.es avatar

@sarajw hah, I bult the same thing on haproxy for a little project just yesterday!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • thenastyranch
  • GTA5RPClips
  • tester
  • InstantRegret
  • DreamBathrooms
  • ngwrru68w68
  • magazineikmin
  • everett
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • cisconetworking
  • megavids
  • khanakhh
  • normalnudes
  • osvaldo12
  • cubers
  • tacticalgear
  • Durango
  • ethstaker
  • modclub
  • anitta
  • provamag3
  • Leos
  • JUstTest
  • lostlight
  • All magazines