Yes, as long as you do that. I don't think you can rely on that.
Then for now not such a service would not be able to use CORS unless they change the way they handle OPTIONS. I think that is acceptable given that supporting authentication in the preflight would be a royal pain.
-- Anne van Kesteren http://annevankesteren.nl/
