The web enforces something called the same-origin policy. By default, we can only access resources that are located at the same origin as the origin of our request. In this case, the origin www.evilwebsite.com tried to access cross-origin resources from www.bank.com. The browser can now allow certain cross- Origin responses which would’ve normally been blocked by thesame-Origin policy.

8m read timeFrom dev.to
Post cover image
Table of contents
✋🏼 Same-Origin Policy🔥 Client-side CORS💻 Server-side CORS🚀 Preflighted Requests🍪 Credentials
1 Impression3 Comments