Could someone explain how re-directing from a subdomain (chess.com.foo.bar) somehow got past some same-origin check?
Typically same origin policies are relaxed for things like images by default [0]. So they came up with a trampoline, they created a chess.com.theirDomain.tld to get past the re-upload filter, which in turn returned a redirect, which the browser followed.
[0] https://developer.mozilla.org/en-US/docs/Web/Security/Same-o...