A closer look at OpenAI’s API uncovers some shaky ground: misconfigured CORS headers, missing X-Frame-Options, no input validation, and borked HTTP status handling. Large uploads? Boom..crash! CORS preflight requests? Straight-up denied. So much for smooth browser support.










