vitvad / Access-Control-Allow-Origin

Chrome extension: https://chrome.google.com/webstore/detail/allow-control-allow-origi/nlfbmbojpeacfghkpbjhddihlkkiljbi
212 stars 73 forks source link

evil.com? #45

Open leocaseiro opened 7 years ago

leocaseiro commented 7 years ago

Hi, I really like this extension and I use in many of my development, however, I don't get why there's a request with evil.com?

yangfan1122 commented 7 years ago

I got the same situation, and felt so weird

vitvad commented 7 years ago

this extension was written on the knees with a beer one evening as a potentially useful tool, next week I found out that chrome has flags so it was almost no sense in it. (I still wondering how this extension got 200k+ downloads) As for evil.com - it was joke and small reminder that we need take care about what we allow in our CORS headers.

I know that many people complain about this and some other stuff, so I promise to update extension till next monday (29/05/2017) and make this field editable. Need finally proceed with development and make it useful again :)

leocaseiro commented 7 years ago

Hi @vitvad I really appreciate your answer. Thanks for that. It would be nice make it editable.

One evening? You are a legend 😄

vitvad commented 7 years ago

(29/05/2017) ....

I so fucking lazy...

anthify commented 6 years ago

@vitvad my heart sank when I saw that header

StillLearnin commented 6 years ago

And mine...

mauriciojaramillo commented 6 years ago

Me too ...

prithvin commented 6 years ago

Me too! Never thought I'd get a notification from sentry with evil.com in it. Would it be possible to allow users to pass in a blank origin instead of evil.com?

mountainguan commented 6 years ago

so...still not updated

fire-stone commented 6 years ago

Is this updated in the year 2018?

dundat11 commented 6 years ago

@fire-stone It has not been updated, you can see the header set as a var in background.js which was last updated sometime in October of 2015.

ykcai commented 5 years ago

haha i laughed at this