Security News > 2016 > January > Cross-Origin Resource Sharing (CORS) needs to be used without wildcard domain matching, and via authentication (for write access at least, if not read too) (Reddit)