phplist3 icon indicating copy to clipboard operation
phplist3 copied to clipboard

Ajax / XMLHttpRequests are still processed - even from unallowed origins

Open nepomuc opened this issue 5 years ago • 1 comments

When performing an Ajax / XMLHttp request against a subsribe-list from an unallowed origin regarding the Access-Control-Allow-Origin header, it's still being processed and the double-opt-in email will be sent. That's probably an unwanted behaviour, right?

nepomuc avatar Oct 29 '20 11:10 nepomuc

Yes, that would be, but that would be a browser issue, as we're telling the browser what should be allowed. What browser did you use to try this?

michield avatar Nov 03 '20 09:11 michield