<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Arpit Jana</title>
    <description>The latest articles on DEV Community by Arpit Jana (@arpitjana2103).</description>
    <link>https://dev.to/arpitjana2103</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1921365%2F8c43f492-40f3-4dc7-afd8-d20dd7876518.jpg</url>
      <title>DEV Community: Arpit Jana</title>
      <link>https://dev.to/arpitjana2103</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/arpitjana2103"/>
    <language>en</language>
    <item>
      <title>CORS Explained Simply: Why Browsers Block Your API Requests ?</title>
      <dc:creator>Arpit Jana</dc:creator>
      <pubDate>Thu, 05 Mar 2026 07:58:40 +0000</pubDate>
      <link>https://dev.to/arpitjana2103/cors-explained-simply-why-browsers-block-your-api-requests-5bmh</link>
      <guid>https://dev.to/arpitjana2103/cors-explained-simply-why-browsers-block-your-api-requests-5bmh</guid>
      <description>&lt;p&gt;Every developer eventually encounters the infamous error:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Access to fetch at 'https://api.example.com' from origin 'https://myapp.com'
has been blocked by CORS policy
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;At first glance, it feels like the &lt;strong&gt;server blocked your request&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;But here’s the twist:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The request &lt;strong&gt;was not blocked&lt;/strong&gt;.&lt;br&gt;
The browser simply &lt;strong&gt;refused to let your JavaScript read the response&lt;/strong&gt;.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Understanding this single idea makes CORS far less mysterious.&lt;/p&gt;

&lt;p&gt;Let's break it down step by step.&lt;/p&gt;




&lt;p&gt;🟦 &lt;strong&gt;1. What is CORS?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CORS (Cross-Origin Resource Sharing)&lt;/strong&gt; is a &lt;strong&gt;browser-enforced security rule&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It controls whether &lt;strong&gt;JavaScript running in the browser is allowed to read a response coming from another origin&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Important truths:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🚨 CORS is &lt;strong&gt;not a server security system&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;🚨 CORS does &lt;strong&gt;not block network requests&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;🚨 CORS is &lt;strong&gt;enforced only by browsers&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Tools like &lt;strong&gt;Postman, curl, or server-side code are not restricted by CORS&lt;/strong&gt;.&lt;/p&gt;




&lt;p&gt;🟦 &lt;strong&gt;2. What is an Origin?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An &lt;strong&gt;Origin&lt;/strong&gt; is defined by three components together:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Origin = Protocol + Host + Port
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Examples:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;URL&lt;/th&gt;
&lt;th&gt;Origin&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://frontend.com" rel="noopener noreferrer"&gt;https://frontend.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://frontend.com:443" rel="noopener noreferrer"&gt;https://frontend.com:443&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="http://frontend.com" rel="noopener noreferrer"&gt;http://frontend.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;❌ different origin (protocol)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://frontend.com:3000" rel="noopener noreferrer"&gt;https://frontend.com:3000&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;❌ different origin (port)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://api.frontend.com" rel="noopener noreferrer"&gt;https://api.frontend.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;❌ different origin (subdomain)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;👉 Even a &lt;strong&gt;small change&lt;/strong&gt; creates a different origin.&lt;/p&gt;




&lt;p&gt;🟦 &lt;strong&gt;3. Same-Origin Policy (The Default Rule)&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Browsers enforce something called the &lt;strong&gt;Same-Origin Policy&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It states:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;JavaScript can only read responses from the &lt;strong&gt;same origin&lt;/strong&gt; by default.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Frontend → https://frontend.com
Backend  → https://api.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Result:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;❌ JavaScript cannot read the response
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Unless the server explicitly allows it using &lt;strong&gt;CORS headers&lt;/strong&gt;.&lt;/p&gt;




&lt;p&gt;🟦 &lt;strong&gt;4. The &lt;code&gt;Origin&lt;/code&gt; Request Header&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When a browser sends a &lt;strong&gt;cross-origin request&lt;/strong&gt;, it automatically attaches this header:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Origin: https://frontend.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Key details:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Added &lt;strong&gt;automatically by the browser&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Cannot be modified by JavaScript&lt;/li&gt;
&lt;li&gt;Tells the server where the request came from&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It basically means:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“This request originated from &lt;a href="https://frontend.com%E2%80%9D" rel="noopener noreferrer"&gt;https://frontend.com”&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Again, remember:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Postman and curl do not enforce CORS&lt;/strong&gt;, which is why APIs often work there but fail in the browser.&lt;/p&gt;




&lt;p&gt;🟦 &lt;strong&gt;5. The &lt;code&gt;Access-Control-Allow-Origin&lt;/code&gt; Response Header&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The server decides whether the browser should allow access.&lt;/p&gt;

&lt;p&gt;Example response header:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Access-Control-Allow-Origin: https://frontend.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Meaning:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Browser, it's safe to expose this response to &lt;a href="https://frontend.com%E2%80%9D" rel="noopener noreferrer"&gt;https://frontend.com”&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Common cases:&lt;/p&gt;

&lt;p&gt;🟢 &lt;strong&gt;Allow a specific origin&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Access-Control-Allow-Origin: https://frontend.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;🟢 &lt;strong&gt;Allow all origins&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Access-Control-Allow-Origin: *
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is common for &lt;strong&gt;public APIs&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;However:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;* cannot be used with cookies or credentials
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  🎬 The Real CORS Flow (The Part Most Developers Miss)
&lt;/h2&gt;

&lt;p&gt;Let's walk through what actually happens.&lt;/p&gt;

&lt;p&gt;▶️ &lt;strong&gt;Setup&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Frontend: https://myapp.com
Backend : https://api.mybackend.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;User is logged in and has a &lt;strong&gt;session cookie&lt;/strong&gt;.&lt;/p&gt;




&lt;p&gt;▶️ &lt;strong&gt;Step 1 — JavaScript Sends a Request&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nf"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;https://api.mybackend.com/profile&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;credentials&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;include&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This tells the browser:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;This is a cross-origin request and I want to include cookies.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Without &lt;code&gt;credentials: "include"&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;❌ Cookies are not sent
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;▶️ &lt;strong&gt;Step 2 — Browser Checks if a Preflight is Needed&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Browsers classify requests into &lt;strong&gt;simple&lt;/strong&gt; and &lt;strong&gt;complex&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;🟢 &lt;strong&gt;Simple requests (no preflight)&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Methods: GET, POST, HEAD&lt;/li&gt;
&lt;li&gt;Safe headers&lt;/li&gt;
&lt;li&gt;Standard content types&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;🟠 &lt;strong&gt;Complex requests (require preflight)&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;PUT / DELETE / PATCH&lt;/li&gt;
&lt;li&gt;Custom headers&lt;/li&gt;
&lt;li&gt;Authorization headers&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a request is complex, the browser performs a &lt;strong&gt;preflight check&lt;/strong&gt; first.&lt;/p&gt;




&lt;p&gt;▶️ &lt;strong&gt;Step 3 — The Preflight Request&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The browser sends an &lt;strong&gt;OPTIONS request&lt;/strong&gt; automatically.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;OPTIONS /profile HTTP/1.1
Host: api.mybackend.com
Origin: https://myapp.com
Access-Control-Request-Method: GET
Access-Control-Request-Headers: authorization
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is basically the browser asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Hey server, is it okay if myapp.com sends this request?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;No cookies are sent yet.&lt;/p&gt;




&lt;p&gt;▶️ &lt;strong&gt;Step 4 — Server Responds to Preflight&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The server must respond with permission headers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;HTTP/1.1 204 No Content
Access-Control-Allow-Origin: https://myapp.com
Access-Control-Allow-Credentials: true
Access-Control-Allow-Methods: GET, POST, PUT
Access-Control-Allow-Headers: authorization, content-type
Access-Control-Max-Age: 86400
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Meaning:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Header&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Allow-Origin&lt;/td&gt;
&lt;td&gt;which origin is allowed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Allow-Credentials&lt;/td&gt;
&lt;td&gt;cookies allowed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Allow-Methods&lt;/td&gt;
&lt;td&gt;permitted HTTP methods&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Allow-Headers&lt;/td&gt;
&lt;td&gt;permitted request headers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Max-Age&lt;/td&gt;
&lt;td&gt;how long the permission is cached&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;🚨 &lt;strong&gt;Critical rule&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If using cookies:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Access-Control-Allow-Origin cannot be "*"
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;▶️ &lt;strong&gt;Step 5 — The Actual Request Happens&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;After preflight approval, the browser sends the real request.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;GET /profile
Origin: https://myapp.com
Cookie: sessionId=abc123
Authorization: Bearer token
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now the server processes the request normally.&lt;/p&gt;




&lt;p&gt;▶️ &lt;strong&gt;Step 6 — Server Sends Response&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://myapp.com
Access-Control-Allow-Credentials: true
Content-Type: application/json
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Response body:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;{ "name": "John", "email": "john@example.com" }
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;▶️ &lt;strong&gt;Step 7 — Browser Performs the Final Security Check&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The browser verifies:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;credentials: "include"&lt;/code&gt; used&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Access-Control-Allow-Credentials: true&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;specific &lt;code&gt;Access-Control-Allow-Origin&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;cookies allow cross-site usage&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If everything passes:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;✅ JavaScript receives the response
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If not:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;❌ Browser blocks JavaScript access
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;🟥 &lt;strong&gt;The Most Misunderstood Truth About CORS&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Many developers believe:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;CORS blocks requests from reaching the server.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;But the reality is different.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Server  → response sent
Network → response delivered
Browser → response received
JS      → access blocked
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The browser simply places the response &lt;strong&gt;behind a security curtain&lt;/strong&gt;.&lt;/p&gt;




&lt;p&gt;🟦 &lt;strong&gt;Proof: Check DevTools&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Open &lt;strong&gt;Network tab&lt;/strong&gt; in your browser.&lt;/p&gt;

&lt;p&gt;Often you'll see:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Status: 200 OK
Response body present
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Yet your code throws:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;TypeError: Failed to fetch
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Because:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The browser blocked JavaScript from reading the response.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;🟦 &lt;strong&gt;Side Effects Still Happen&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Even if CORS blocks the response:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;cookies were sent&lt;/li&gt;
&lt;li&gt;server logic executed&lt;/li&gt;
&lt;li&gt;database changes happened&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;POST /transfer-money
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Possible result:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;✅ money transferred
❌ JavaScript cannot read the response
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is why &lt;strong&gt;CSRF protection exists&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Important distinction:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;CORS != CSRF protection
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;🟦 &lt;strong&gt;Why CORS Exists&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Without CORS:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Any website could call your APIs&lt;/li&gt;
&lt;li&gt;Cookies would attach automatically&lt;/li&gt;
&lt;li&gt;Sensitive user data could be stolen&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;CORS protects:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;✅ users
✅ browser environment
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But not:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;❌ servers
❌ databases
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;🟪 &lt;strong&gt;The Mental Model That Makes CORS Easy&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Origin header&lt;/td&gt;
&lt;td&gt;browser introducing itself&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Allow-Origin&lt;/td&gt;
&lt;td&gt;server's guest list&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Browser&lt;/td&gt;
&lt;td&gt;security bouncer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;JavaScript&lt;/td&gt;
&lt;td&gt;requesting access&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Or remember this line:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;CORS decides who can READ, not who can SEND.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;🟢 &lt;strong&gt;Final One-Line Summary&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;CORS is a browser security rule that determines whether JavaScript is allowed to read cross-origin responses, even though the request and response already happened successfully.&lt;/p&gt;




&lt;p&gt;🧩 &lt;strong&gt;Cover Image Icons Credits&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.flaticon.com/free-icons/server" rel="noopener noreferrer"&gt;Server icons by smashingstocks - Flaticon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.flaticon.com/free-icons/webpage" rel="noopener noreferrer"&gt;Webpage icons by Freepik - Flaticon&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>javascript</category>
      <category>backend</category>
      <category>systemdesign</category>
    </item>
  </channel>
</rss>
