Jump to content

MediaWiki:Apihelp-main-param-crossorigin

Page contents not supported in other languages.
M530x529S10018470x471S10641507x501S26505486x480S21600500x494 IslamData (ase)

When accessing the API using a cross-domain AJAX request (CORS) and using a session provider that is safe against cross-site request forgery (CSRF) attacks (such as OAuth), use this instead of origin=* to make the request authenticated (i.e., not logged out). This must be included in any pre-flight request, and therefore must be part of the request URI (not the POST body).

Note that most session providers, including standard cookie-based sessions, do not support authenticated CORS and cannot be used with this parameter.

M513x542S1ce50491x458S22a00492x492S14c50487x511 M530x529S10018470x471S10641507x501S26505486x480S21600500x494 https://ase.islamd.ru/MediaWiki:Apihelp-main-param-crossorigin