Http cross origin resource sharing

From wikinotes

The Cross-Origin Resource Sharing policy (CORS) is configured in request/response http headers.
It determines which sources (domains/schemes/ports) other than itself the browser should permit to load resources from (ex: css, javascript, ...).

Documentation

MDN https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS
wikipedia https://en.wikipedia.org/wiki/Cross-origin_resource_sharing

Examples

TODO:

todo

HTTP Headers

Request

Origin
Access-Control-Request-Method
Access-Control-Request-Headers

Response

Access-Control-Allow-Origin
Access-Control-Allow-Credential
Access-Control-Expose-Headers
Access-Control-Max-Age
Access-Control-Allow-Methods
Access-Control-Allow-Headers