Hot Take: CORS Is stupid and useless and a complete failure.
by default. New kinds of scripts are public by default and don't support credentials, so CORS not needed. Even intranets are vulnerable 2/
-
-
to Function.prototype.toString so don't give the illusion of security. New kind of content so doesn't affect billions of existing pages 3/3
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.