freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #44 of 45

cors · cross-origin requests

RestaVSThe 401 Bandit
Resta saysCORS is the browser rule that controls which sites may call an API from the page.

Browsers block cross-origin requests by default (the Same-Origin Policy). CORS (Cross-Origin Resource Sharing) is how a server opts in: it returns Access-Control-Allow-Origin (and related) headers naming who's allowed. Crucially, CORS is enforced by the browser, configured by the server — your front-end can't fix a CORS error; the API must send the right headers.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain why a CORS error is the API’s job to fix, not the client’s.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>browser blocks call to other-origin API
unless the API replies:
  Access-Control-Allow-Origin: https://your.site</pre></body></html>
▶ Open the interactive comic issue
‹ Csrf · Same-Site · Double SubmitCors · Preflight · The OPTIONS Round-Trip ›