CORS Security Guide

Same-Origin Policy (SOP)

Browsers block cross-origin requests by default. Two URLs have the same origin if their protocol, host, and port all match.

CORS Headers Reference

Access-Control-Allow-OriginSpecify allowed origin(s). Never use * with credentials.
Access-Control-Allow-MethodsList allowed HTTP methods
Access-Control-Allow-HeadersList allowed request headers
Access-Control-Allow-CredentialsSet true only when credentials (cookies) needed
Access-Control-Max-AgeCache preflight response (seconds)