Software → Security
CORS
A browser security mechanism that controls which origins may access resources from another origin.
Motivation
CORS exists because real systems need a practical way to handle a recurring engineering problem. Understanding it helps you see why nearby concepts in the graph matter rather than memorizing isolated definitions.
Where it fits
CORS belongs to the product track in the web applications layer. It is usually learned together with concepts such as HTTP, API.
Mental model
Think of CORS as one piece of a larger system. It either provides a capability, constrains how other parts work, or gives engineers a shared vocabulary for making design decisions.
Example in practice
When engineers discuss CORS, they usually care about trade-offs: what problem it solves, what complexity it adds, and what assumptions it makes about the surrounding system.
Common mistakes
- Treating CORS as a definition to memorize rather than a tool for reasoning.
- Ignoring the layer it belongs to and applying it at the wrong abstraction level.
- Forgetting the operational or design trade-offs it introduces.