CORS
also: cross-origin resource sharing, cors error, cors policy, cross-origin, access-control-allow-origin
A browser safety rule: a web page can only read data from a different website if that website's server says the page is allowed to.
Cross-Origin Resource Sharing. Browsers stop JavaScript on one origin (scheme, domain and port) from reading responses from another origin unless the server sends headers like Access-Control-Allow-Origin. Some requests trigger a preflight OPTIONS check first. Browsers enforce it; servers only grant permission.
A school only releases a child to adults on the parents' pickup list. The school enforces the rule, but the parents write the list. Anyone not on it leaves empty-handed.
CORS errors confuse beginners and agents alike. Knowing the fix belongs on the server, and should list specific allowed sites, stops an agent from "fixing" it by allowing everyone.
The browser blocks the request because the API doesn't send Access-Control-Allow-Origin for localhost:3000. I'll add your frontend origins to the CORS allowlist.
Fix the CORS error by allowing only our production site and localhost. Don't allow every website to read our API, and explain why it was failing.
Thinking CORS protects your server from other programs. Only browsers enforce it. Scripts and command-line tools like curl ignore it completely.