ajax cross origin request blocked

Microsofts Activision Blizzard deal is key to the companys mobile gaming efforts. The following shows a typical database query in Rails to find the first record in the users table which matches the login credentials parameters supplied by the user. In these cases, explicitly skip CSRF protection on actions that serve JavaScript meant for a