SECURITY / A CONCEPT NOTE
CORS
the browser's same-origin policiy enforcer
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Cross-Origin Resource Sharing (CORS) is a browser mechanism that controls which domains can access resources from your server. When a web app at app.example.com fetches data from api.example.com, the browser sends a preflight OPTIONS request first. The server responds with Access-Control-Allow-Origin headers to permit or deny the cross-origin request.
02 / FOLLOW THE MECHANISM
How a preflight request works
Browser
detects a cross-origin fetch — different domain, protocol, or port than the page's origin.
Browser
sends an
OPTIONSpreflight request withOrigin: https://app.example.comandAccess-Control-Request-Method: POST.Server
responds with
Access-Control-Allow-Origin: https://app.example.com(or*) and the allowed methods/headers.Browser
checks the response. If the origin is not allowed, the browser blocks the actual request with a CORS error.
Actual request
if preflight passes, the browser sends the real
GETorPOSTand exposes the response to JavaScript.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
simulate a cross-origin request
curl -H "Origin: https://evil.com" -v https://api.example.com/datatrigger a preflight manually
curl -X OPTIONS -H "Origin: https://app.example.com" -H "Access-Control-Request-Method: GET" -v https://api.example.com/data05 / CHECK YOURSELF
Could you explain CORS to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identitySIEMcentralized logging and alerting for security events