RootCauseunvalidated
you do not allow your site to be reached from browsers that refuse to serve unspecified servers — your API is on domain1 and I own domain2 where I want to request end points from your server. Tension: you exclude my domain2 from doing so on the client-side and you force such third-parties to send their requests from the server-side.
7a17c336-e70e-4fba-bc79-f910729f6669
you do not allow your site to be reached from browsers that refuse to serve unspecified servers — your API is on domain1 and I own domain2 where I want to request end points from your server. Tension: you exclude my domain2 from doing so on the client-side and you force such third-parties to send their requests from the server-side.