# What are the risks of enabling Cross-origin resource sharing (DISCOURSE\_ENABLE\_CORS)

**URL:** https://meta.discourse.org/t/what-are-the-risks-of-enabling-cross-origin-resource-sharing-discourse-enable-cors/41248
**Category:** Support
**Created:** [3월 18, 2016, 3:15오전 UTC](https://meta.discourse.org/t/what-are-the-risks-of-enabling-cross-origin-resource-sharing-discourse-enable-cors/41248 "2016-03-18T03:15:56Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![meglio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/meglio/32/71444_2.png) [@meglio](https://meta.discourse.org/u/meglio)
#### Post date: [3월 18, 2016, 3:31오전 UTC](https://meta.discourse.org/t/what-are-the-risks-of-enabling-cross-origin-resource-sharing-discourse-enable-cors/41248/5 "2016-03-18T03:31:31Z")

</div>

So, the only really safe way to query API from a different domain would be to allow JSONP: either by origin domain or by api\_username/key, right?

If that’s correct, I’ve seen some discussion about JSONP in [this topic](https://meta.discourse.org/t/cross-origin-resource-sharing-for-api-access-in-javascript/6067) - have it been considered for implementation eventually?

---

_[View the full topic](https://meta.discourse.org/t/what-are-the-risks-of-enabling-cross-origin-resource-sharing-discourse-enable-cors/41248)._
