Ch. 20 · Networking

CORS and Browser Response Access

CORS and Browser Response Access. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

CORS controls how browser scripts access cross-origin responses. It is not a general firewall or substitute for server authorization.

Before you start

You should understand clients, servers, IP addresses and ports. Follow a request through name resolution, connection establishment and application exchange. Distinguish protocol guarantees from deployment policy, and use observations from the relevant layer rather than guessing from one browser error message.

The practical goal is to reason through this situation: An API permits a specified browser origin while checking authentication independently. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Identify browser origin

Scheme, host and port participate in origin comparison.

Step 2: Inspect response access policy

CORS determines whether browser scripts may access the response.

Step 3: Keep server authorization

Non-browser callers are not blocked by browser CORS rules.

Worked scenario

An API permits a specified browser origin while checking authentication independently.

A browser page cannot read an API response because its origin is not permitted, yet a command-line client can send the same request. That does not prove the API is public or protected; authentication and authorization decide that independently. Some cross-origin requests may be sent even when response access is denied.

Common mistake

A request from a non-browser client is not restricted by browser CORS enforcement.

Verify the behavior

Compare browser preflight or response handling with direct authorized and unauthorized API calls.

Interview exercise

Explain a blocked browser call.

Answer and reasoning

Inspect origin, preflight and response headers, then distinguish browser access policy from actual API authorization.

Continue learning

Compare the scenario with the Networking interview questions and test your understanding with the Networking MCQs. For terminology and implementation details, consult the reference material.

More in Networking

read ✓Networking · mid

Networking: DNS Caching and TTL

Understand positive and negative caching, why changes are not instant, and how TTL trades propagation speed against query load.

~2 min readread →
read ✓Networking · easy

Networking: DNS Record Types

Read and choose DNS records: A and AAAA for addresses, CNAME for aliases, and MX and TXT for mail and verification.

~2 min readread →
read ✓Networking · mid

Networking: HTTP Redirects

Choose between 301, 302, 307 and 308, know which preserve the request method, and avoid caching and loop mistakes.

~2 min readread →
esc