Hi, a bit odd me asking a question but I'm a bit rusty.

We've a request from a (non malicious) third party to allow CORS so they 
can have javascript that accesses /id/ and /cgi/export/ to do clever things.

If there's any way to alter the system via these URLs it's a 
cross-site-scripting no-no, and from reviewing the code I *think* that 
those URLs are always read-only.

I thought the REST interface was at /rest/ but it looks like there's 
another one implemented on /id/

-- uses /rest/
-- uses /id/

I suspect that means that it *is* too dangerous to allow cross site JS 
to connect to /id/ which is a pity, but security first, right?


