Skip to content
EduVerse

CORS

In depth

Protocol / format

Also known as: Cross-Origin Resource Sharing

Security mechanism that decides which domains may call an API from the browser.

CORS, explained

Written by EduVerse

What it is

CORS (Cross-Origin Resource Sharing) is a browser security mechanism built on HTTP headers. By default, the browser’s same-origin policy stops a script from reading responses from another origin: a different domain, port or protocol. With CORS headers, the server states which origins are allowed, and the browser enforces that.

Why teams use it

Without that rule, any site you visit could call your bank’s API with your logged-in cookies and read the answer. CORS keeps that protection in place, but lets a server allow trusted origins, such as your own frontend on another domain. Only browsers enforce it: tools like curl or Postman ignore it.

An example from work

Your React app on localhost:3000 calls your API on localhost:8080, and the console says the request was “blocked by CORS policy” because no Access-Control-Allow-Origin header is present. The same request works fine in Postman. The fix belongs on the server, which has to send that header for your frontend’s origin.

Our own explanation, not a quote from the book.

In the book

Sentences from The Software Realm, Decoded that mention CORS, exactly as printed.

    6 more passages about CORS in the full book

    Read every conversation where CORS comes up, with the interactive slides and demos.

    See the book

    Where it fits

    Browser security for cross-origin API calls

    Coverage in the book

    In depth

    Covered in depth: multiple pages with explanations, examples and simulations.

    Appears in