Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Credentialed CORS: bind allowed origins to the response cache key

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

CORS controls whether browser JavaScript can read a cross-origin response; it does not authenticate a caller or protect the API from direct requests. A credentialed browser request cannot use a wildcard allowed-origin response. The server must validate the requesting origin against an explicit list, return that origin only when allowed, and send the credential permission for the permitted case. If the allowed origin varies with the request, intermediary caches need a matching variation key so one origin's response headers are not served to another. Preflight responses have their own method and header contract. Cookies also need a separate site and CSRF design; CORS by itself does not make state-changing operations safe.

Operational decision

An editorial preview runs on a separate hostname and calls a CMS endpoint with a session cookie. The API permits the preview origin and rejects an unlisted origin. A preflight for the publishing action names the allowed method and headers; the actual response carries the same origin decision. The edge varies cached responses by Origin or bypasses shared caching for personalized content. Test the allowed preview origin, a disallowed origin, a request without credentials, and two requests in alternating order through the same cache. The last case catches a cache key that forgot Origin. A public read-only content feed can use a simpler non-credentialed policy, but it should remain separate from editorial operations.

Output
Allowed credentialed response
Access-Control-Allow-Origin: validated request origin
Access-Control-Allow-Credentials: true
Vary: Origin
Cache-Control: private, no-store
Preflight: explicit allowed method and headers
Rejected origin: no readable credentialed response

Cost and verification

An origin allowlist lookup is O(A) with a plain list of A origins or near O(1) with a hashed set; the meaningful cost is preflight latency and cache fragmentation. A cache that varies by Origin may keep multiple variants, while private no-store avoids cross-user reuse at higher origin load. Test both browser enforcement and server authorization. A valid CORS response is not proof that the session has permission to publish.

Common Mistakes

  • Do not combine a wildcard allowed origin with credentialed browser access.
  • Do not rely on CORS as the API authorization layer.
  • Do not cache an origin-specific response without a matching cache policy.

Connected lessons

Practice and check

devops
browser-security
Storage details