Resta saysCORS is the browser rule that controls which sites may call an API from the page.
Browsers block cross-origin requests by default (the Same-Origin Policy). CORS (Cross-Origin Resource Sharing) is how a server opts in: it returns Access-Control-Allow-Origin (and related) headers naming who's allowed. Crucially, CORS is enforced by the browser, configured by the server — your front-end can't fix a CORS error; the API must send the right headers.
Power-ups you unlock
Same-Origin Policy blocks cross-origin calls
Server opts in via Access-Control-Allow-* headers
Enforced by the browser, set by the server
Front-end can’t fix CORS — the API must
The 401 Bandit attacks — common mistakes
Trying to fix CORS in front-end code
Access-Control-Allow-Origin: * with credentials (invalid)
Confusing CORS errors with network errors
Boss battleExplain why a CORS error is the API’s job to fix, not the client’s.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>browser blocks call to other-origin API
unless the API replies:
Access-Control-Allow-Origin: https://your.site</pre></body></html>