Skip to content

Commit 91babb9

Browse files
authored
Update Api docs for credentialed requests (#221)
#220
1 parent 522d989 commit 91babb9

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

docs/api.rst

+3
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,9 @@ cross origins, simply set the `supports_credentials` option to `True`. E.G.
4646
def helloWorld():
4747
return "Hello, %s" % session['username']
4848
49+
50+
The above code enables Flask backend to accept cookies to be submitted from cross origin sites. But if you are sending Xhr requests (ajax calls) to a cross-origin server, by default chrome or any modern browser won't send cookies and session with the request. You should use ``withCredentials = True`` while sending Xhr request to enable that. You should keep in mind about the necessary security concerns. Related MDN doc: https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest/withCredentials
51+
4952
Using `CORS` with Blueprints
5053
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
5154

0 commit comments

Comments
 (0)