ZZomato·Tech KnowledgeL1System Design

CORS (Cross-Origin Resource Sharing)

Problem What is CORS, and what problem does it exist to solve? Explain its use cases.

Be ready to discuss

  • The baseline it relaxes: the Same-Origin Policy blocks a page from reading responses from a different origin (scheme + host + port); CORS is the opt-in mechanism by which the target server grants an exception.
  • Key point often missed: CORS is enforced by the browser, not the server — the request usually still reaches the server, and the browser withholds the response from JS. It is not a defence against non-browser clients (curl, server-to-server).
  • Response headers: Access-Control-Allow-Origin (and why * cannot be combined with credentials), -Allow-Methods, -Allow-Headers, -Expose-Headers, -Max-Age, -Allow-Credentials.
  • Preflight: what makes a request "simple" versus one that triggers an OPTIONS preflight (custom headers, non-simple content types, methods beyond GET/POST/HEAD), and the latency cost of a preflight per request.
  • Credentialed requests: cookies/Authorization require Allow-Credentials: true plus an exact origin echo — and why echoing back an arbitrary Origin header is a real vulnerability.
  • Caching interaction: reflecting Origin per request without Vary: Origin poisons shared/CDN caches by serving one origin's header to another.
  • Use cases: an SPA on one domain calling an API on another, CDN-hosted fonts and assets, public read-only APIs — while blocking malicious cross-origin reads of authenticated data by default.
asked …
LeaderboardSalaryAccount