CORS and Auth Tokens: JWT vs Cookies
CORS gets messy the moment authentication enters the picture. A simple public GET with Access-Control-Allow-Origin: * is easy. GitHub’s API does exactly that for many responses: access-control-allow-origin: * access-control-expose-headers: ETag, Link, Location, Retry-After, X-GitHub-OTP, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, X-RateLimit-Resource, X-RateLimit-Reset, X-OAuth-Scopes, X-Accepted-OAuth-Scopes, X-Poll-Interval, X-GitHub-Media-Type, X-GitHub-SSO, X-GitHub-Request-Id, Deprecation, Sunset, Warning That works because a browser can fetch public data without credentials. The moment you send cookies or an Authorization header, the rules change. ...