magento2-cors
magento2-cors copied to clipboard
docs(security): add documentation around why the "*" should generally be recommended against.
Currently, we recommend against using the wildcard access-control-allow-origin header, we should explain precisely why.