No 'Access-Control-Allow-Origin' header is present on the requested resource

This is not secure.

Your password is exposed in the javascript source.

looking at the screenshots both servers are frappe servers.

user frappeclient and server side calls, you won’t face cors issue there.

1 Like