Is it just me, or does anyone else think the way CORS works right now is completely bass-ackwards? We have a page served by Host A that wants to access resources on Host B. Why is it that Host B has to allow this and not Host A? If I compromise a script on Host A, of course I'll also add the needed headers in the reply by Host B! Isn't it a lot more sensible that Host A should include a header that says "you are allowed to also download resources from Host B"?