CORS error persists in oAuth even after setting header

But a state should still be unique between oAuth requests to prevent CSRF attacks

1 Like