CORS preflight描述
Chrome is deprecating direct access to private network endpoints from public websites as part of the Private Network Access (PNA) specification.
Chrome will start sending a CORS preflight request ahead of any private network request for a subresource, which asks for explicit permission from the target server. This preflight request will carry a new header, Access-Control-Request-Private-Network: true, and the response to it must carry a corresponding header, Access-Control-Allow-Private-Network: true.
The aim is to protect users from cross-site request forgery (CSRF) attacks targeting routers and other devices on private networks. These attacks have affected hundreds of thousands of users, allowing attackers to redirect them to malicious servers.Google Chrome preflight12

谷歌Chrome即将实施新的Private Network Access规范,要求从公共网站访问私网资源前发送预检请求,旨在防止跨站请求伪造攻击。通过Access-Control-Request-Private-Network头,浏览器确保服务器授权访问,提升用户安全防护。
最低0.47元/天 解锁文章
1201

被折叠的 条评论
为什么被折叠?



