CORS
In depthProtocol / format
Also known as: Cross-Origin Resource Sharing
Security mechanism that decides which domains may call an API from the browser.
CORS, explained
Written by EduVerseWhat it is
CORS (Cross-Origin Resource Sharing) is a browser security mechanism built on HTTP headers. By default, the browser’s same-origin policy stops a script from reading responses from another origin: a different domain, port or protocol. With CORS headers, the server states which origins are allowed, and the browser enforces that.
Why teams use it
Without that rule, any site you visit could call your bank’s API with your logged-in cookies and read the answer. CORS keeps that protection in place, but lets a server allow trusted origins, such as your own frontend on another domain. Only browsers enforce it: tools like curl or Postman ignore it.
An example from work
Your React app on localhost:3000 calls your API on localhost:8080, and the console says the request was “blocked by CORS policy” because no Access-Control-Allow-Origin header is present. The same request works fine in Postman. The fix belongs on the server, which has to send that header for your frontend’s origin.
Our own explanation, not a quote from the book.
In the book
Sentences from The Software Realm, Decoded that mention CORS, exactly as printed.
6 more passages about CORS in the full book
Read every conversation where CORS comes up, with the interactive slides and demos.
Where it fits
Browser security for cross-origin API calls
Coverage in the book
Covered in depth: multiple pages with explanations, examples and simulations.