Discussion on: Understanding CORS

Andrew Luca
  • CSRF is Cross-site request forgery
  • CORS is Cross-origin resource sharing

If no one from another origin is able to make requests to your site (CORS disabled),
then CSRF is redundant imo.

Maximilian Burszley

But that's not what CORS does. Re-read the warning in the article.