CORS (Cross-Origin Resource Sharing)
Problem What is CORS, and what problem does it exist to solve? Explain its use cases.
Be ready to discuss
- The baseline it relaxes: the Same-Origin Policy blocks a page from reading responses from a different origin (scheme + host + port); CORS is the opt-in mechanism by which the target server grants an exception.
- Key point often missed: CORS is enforced by the browser, not the server — the request usually still reaches the server, and the browser withholds the response from JS. It is not a defence against non-browser clients (curl, server-to-server).
- Response headers:
Access-Control-Allow-Origin(and why*cannot be combined with credentials),-Allow-Methods,-Allow-Headers,-Expose-Headers,-Max-Age,-Allow-Credentials. - Preflight: what makes a request "simple" versus one that triggers an
OPTIONSpreflight (custom headers, non-simple content types, methods beyond GET/POST/HEAD), and the latency cost of a preflight per request. - Credentialed requests: cookies/Authorization require
Allow-Credentials: trueplus an exact origin echo — and why echoing back an arbitraryOriginheader is a real vulnerability. - Caching interaction: reflecting
Originper request withoutVary: Originpoisons shared/CDN caches by serving one origin's header to another. - Use cases: an SPA on one domain calling an API on another, CDN-hosted fonts and assets, public read-only APIs — while blocking malicious cross-origin reads of authenticated data by default.
asked …