Technical reference
CORS: a browser reading rule is not API authentication
Understand why an API can fail in a browser yet remain reachable, and why removing a CORS error can create a different problem.
Research articles and reference entries are published in English. Navigation is available in seven languages.
In this article
What the browser is checking
Cross-Origin Resource Sharing lets a server state which origins may read a response through browser JavaScript. A website and an API on different origins often need this arrangement. Some requests trigger an OPTIONS preflight before the actual request; qualifying simpler requests can be sent without one.
That distinction is easy to miss: a blocked response does not always mean the server never received a request. A CORS failure is also different from an authentication failure or a blockchain node being unavailable. Inspect the browser’s network and console output before assigning a cause.
Do not turn a login problem into a data leak
For a credentialed cross-origin response, the server needs a permitted explicit origin and the appropriate credentials header. A wildcard origin is not accepted for that credentialed sharing. Reflecting every supplied Origin while allowing credentials effectively discards the intended allowlist.
CORS does not replace server-side permission checks. A non-browser client does not become an authorised user because it can make an HTTP request. Likewise, a permitted web origin still needs a valid session and permission for the particular object it requests.
Writes need their own protection
Cross-site request forgery concerns unwanted actions made with a user’s ambient credentials. An attacker may not need to read the response to cause harm. Cookie policy, request validation and CSRF protections therefore remain relevant even when CORS is configured narrowly.
For an API you operate, test an allowed origin, a disallowed origin, a request with no valid session and a session attempting another user’s data. These cases exercise different boundaries. Fix the observed configuration problem at the server; asking users to disable browser security hides the symptom and weakens their protection elsewhere.
