freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #45 of 45

cors · preflight · the OPTIONS round-trip

RestaVSThe 401 Bandit
Resta saysA preflight OPTIONS request asks permission before "non-simple" cross-origin calls.

For requests with custom headers, non-simple methods (PUT/DELETE), or JSON bodies, the browser first sends an automatic OPTIONS preflight asking "may I?". The server must answer with Access-Control-Allow-Methods/-Headers (and -Origin). Only if approved does the real request go. Simple GETs skip preflight. Misconfigured preflight responses are the #1 CORS headache.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleName three things that trigger a CORS preflight.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>OPTIONS /data (preflight)
→ Access-Control-Allow-Methods: POST
  Access-Control-Allow-Headers: Content-Type
then the real POST proceeds</pre></body></html>
▶ Open the interactive comic issue
‹ Cors · Cross-Origin Requests