What is Nostr?
Andy Alness [ARCHIVE] /
npub1xlj…fzv5
2023-06-07 15:21:16
in reply to nevent1q…83nd

Andy Alness [ARCHIVE] on Nostr: 📅 Original date posted:2014-05-11 📝 Original message:Would it be a terrible ...

📅 Original date posted:2014-05-11
📝 Original message:Would it be a terrible idea to amend BIP 70 to suggest implementors include
a "Access-Control-Allow-Origin: *" response header for their payment
request responses? I don't think this opens up any useful attack vectors.

I ask because this would make it practical for pure HTML5 web wallets to
use the payment protocol entirely in-browser. Without this I think it would
be necessary for the server hosting the wallet's HTML to fetch payment
requests on the browser's behalf. This is somewhat inelegant and has
security/resource implications for the back-end.

-Andy
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140511/0ad12a9d/attachment.html>;
Author Public Key
npub1xljjfnrwkp7tg7lyc2624rd2pt5cht3tna00wqad290wxkjw0t7qvkfzv5