The default CORS policy: - Sends Access-Control-Allow-Origin: * - Sends no Access-Control-Allow-Credentials - Sends no Access-Control-Expose-Headers - Sends Access-Control-Allow-Methods: GET, HEAD, POST - Reflects request's Access-Control-Request-Headers as Access-Control-Allow-Headers - Sends no Access-Control-Max-Age
The default CORS policy: - Sends Access-Control-Allow-Origin: * - Sends no Access-Control-Allow-Credentials - Sends no Access-Control-Expose-Headers - Sends Access-Control-Allow-Methods: GET, HEAD, POST - Reflects request's Access-Control-Request-Headers as Access-Control-Allow-Headers - Sends no Access-Control-Max-Age