My browser which has loaded https://www.cashrewards.com.au/shop
, is making a request to the following domain, as you can see in the screenshot:
https://e-11283.adzerk.net
Why is this response not blocked by the same origin policy?
If the .gif being downloaded behind the scenes is on another domain, then shouldn’t the response be blocked by the Same Origin Policy since it has access-control-allow-origin: undefined
?
I don’t understand why undefined is used, but since it’s not *
or cashrewards.com.au
, I would have thought the response would be blocked?
3