The CORS Demos

Thurs 5th March 20

On a recent test, I had to do some work on what turned out to be a badly configured CORS policy. Seeing as I hadn't dug into CORS in a while, it took me a bit of reading to remember what response headers meant what, and what situations were affected by those headers.

I spoke to a few people who said they had the same problem, so I decided to put together this set of demos where I've tried to document and demonstrate each of the different situations. Hopefully this will help us all remember next time.

If you think I've missed anything, or want something extra adding, get in touch.

Play the CORS Demos.


Some useful reference material to help further research.

