Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 5954169
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 22, 20262026-05-22T17:55:57+00:00 2026-05-22T17:55:57+00:00

I am making a page that responds to an AJAX request with a certain

  • 0

I am making a page that responds to an AJAX request with a certain string when another certain string is provided as a GET variable. In order to avoid problems with the “same origin” policy, I have found that I can include this line of PHP at the top of the page:

header('Access-Control-Allow-Origin: *');

There’s no sensitive data being passed whatsoever, it’s actually keywords passed back and forth from several different domains, (its an SEO related application). Due to this, hundreds of different domains will be using it, so if possible I would like to avoid specifying each one. Are there any risks to using this line? If so, what are they?

Also, if this page was located under an HTTPS URL is it still accessible?

Any advice, suggestions or concerns are most welcome. Thank you!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-22T17:55:58+00:00Added an answer on May 22, 2026 at 5:55 pm

    If the access truly is public, I’d say this is a good solution. However, if you want to limit the access to your site, you’ll probably want to list explicitly each domain origin allowed.

    Since you say your response doesn’t include any sensitive information, you probably don’t need to worry about hosting your service over HTTPS. The one reason you might is if a client HTTPS page tries to access your non-HTTPS service. In that case, I would guess they’d get a warning about unsecure information being sent/received when your AJAX service is called, and maybe even just a silent fail. If this is a common enough case, then I’d say looking into the HTTPS service. Make sure your HTTPS certificate is certified properly, because if the client’s browser cannot verify the certificate the AJAX request will silently fail (as opposed to prompting when you navigate directly to an HTTPS page)! Also, I don’t know how it will go in your case, but whenever I’ve worked with HTTPS, I’ve usually had to tweak things to get them to function properly.

    Long story short, I’d start with HTTP and then evaluate the need of HTTPS. Good luck!

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm making a ajax request to a page that does some expensive operations (re-indexing
I'm making a website that tend to handle all the request in one page
I'm working on a web page where I'm making an AJAX call that returns
I am making a jQuery Ajax form submit to a PHP page that I
I have a page that is making an XML POST-Request to an URL on
I have a PHP page that gets its content by making an HTTP request
I'm making an AJAX call to a page that returns XML. It turns out
I'm making an aspx page that can edit books. A book is an complex
OK, say that my application is emitting (x86) instructions into memory, making the page
I am making a configuration page, that splits a category tree over 3 columns

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.