-
Type:
Change Request
-
Resolution: Persuasive
-
Priority:
Medium
-
FHIR Core (FHIR)
-
STU3
-
FHIR Infrastructure
-
Normative
-
REST (http)
-
-
Grahame Grieve/John Moehrke: 11-0-0
-
Enhancement
-
Non-substantive
-
STU3
There is a "Note" recommending CORS. This is a security recommendation and should not appear on the http page. Further the use of CORS is not an appropritate gross security recommendation, as it is only appropriate under very specific conditions. CORS can be very dangerous for the security of a system.
Please remove CORS recommendation from the http page.
Note another useful reference for CORS https://www.moesif.com/blog/technical/cors/Authoritative-Guide-to-CORS-Cross-Origin-Resource-Sharing-for-REST-APIs/
- is voted on by
-
BALLOT-4764 Negative - John Moehrke : 2018-May-FHIR R4 INFRASRUCTURE R1
- Balloted