freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #7 of 45

response headers · cors · cache · set-cookie

RestaVSThe 401 Bandit
Resta saysResponse headers describe the result: content type, caching rules, CORS, and cookies.

The server answers with headers too. Content-Type tells you the body's format; Cache-Control/ETag govern caching; Set-Cookie stores session data; Access-Control-Allow-Origin handles CORS; Location points at a created/redirected resource. Reading these is how clients behave correctly without guessing.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleName the response header that enables cross-origin browser access.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>Content-Type: application/json
Cache-Control: max-age=300
ETag: "abc123"
Access-Control-Allow-Origin: *</pre></body></html>
▶ Open the interactive comic issue
‹ Request Headers · Accept · Auth · Content-TypeUrls · Scheme · Host · Path · Query · Fragment ›