> Again, CORS does not protect, the SOP does :-)
This is simply false. You are somehow wrongly assuming that only same-origin requests exist or are needed. This scenario never existed in the real world beyond the scope of small personal projects.
This is simply false. You are somehow wrongly assuming that only same-origin requests exist or are needed. This scenario never existed in the real world beyond the scope of small personal projects.
So it is not CORS that protects, since it restricts nothing, but SOP (potentially relaxed by CORS).
No they are not making that assumption.