https://bugzilla.wikimedia.org/show_bug.cgi?id=25886

--- Comment #3 from Derk-Jan Hartman <hart...@videolan.org> 2010-11-12 17:11:51 
UTC ---
I think this could be solved by simply adding the header:

Access-Control-Allow-Origin: *

to all bits.wikimedia.org requests ? Unless we have non-public data that comes
from that server, but I doubt that such data uses the bits server, because it
would not be cache-able.

Geoiplookup has a similar security issue I guess, but that does carry sensitive
data, and thus needs specific Origin targeting (API has this I believe).

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to