Configuring cross-origin access and understanding when CSRF protection matters for an API
Open on Cached Info