CORS, CSRF and CSP get the job done;)