What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A CORS error does not necessarily mean the browser stopped a request from reaching the server. If a preflight check fails, the browser does not send the intended preflighted request. But for a request that does not require preflight, the server may receive and process it even when the browser later prevents page JavaScript from reading the response. CORS controls browser access to cross-origin responses; it is not server-side authorization.

What CORS controls

A web page’s origin is its scheme, host, and port. The same-origin policy restricts how scripts on one origin interact with resources on another. Cross-Origin Resource Sharing (CORS) lets a server tell browsers, through response headers such as Access-Control-Allow-Origin, which cross-origin responses a script may access. It is the browser that enforces this permission; CORS is not a general network firewall or an access-control check on the server. MDN’s CORS guide explains the mechanism.

Did the browser send the request?

It depends on where the CORS check failed. Some cross-origin requests need a preflight: before sending the intended operation, the browser sends an OPTIONS request describing the planned method and headers. If the preflight response does not permit the operation, the browser does not send that intended preflighted request. Other requests can be sent without a preflight. If such a request reaches the server but its response fails the CORS check, the browser can withhold the response from page JavaScript even though the server may already have processed the request. MDN describes preflighted requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Failure point What happens What to check
Preflight rejected The browser sends OPTIONS, but does not send the intended preflighted operation. The preflight response’s permitted origin, method, and headers.
Response rejected by CORS The request may have reached and been processed by the server, but page JavaScript cannot read the response. The actual response’s CORS headers and, if available, the server’s logs.

That is why a console message saying a request was blocked is not, by itself, proof that the server did nothing. The browser limits the detail exposed to page JavaScript; the developer console is where you can see the specific CORS failure reason. MDN illustrates an error as “Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at [some site]”. See MDN’s CORS error guidance.

Why CORS is not server security

CORS determines whether browser scripts can read a cross-origin response. It does not authenticate a caller, decide whether a user may perform an operation, or guarantee that a request was never made. The server must still authenticate callers and authorize each operation. Cross-origin writes also need appropriate defenses against Cross-Site Request Forgery (CSRF); CORS should not replace those protections. MDN’s same-origin policy guidance discusses cross-origin network access and CSRF protections.

Credentialed requests need an explicit origin

For a credentialed CORS request, the server must explicitly allow the requesting origin and return Access-Control-Allow-Credentials: true. A wildcard Access-Control-Allow-Origin: * is not accepted for credentialed access. These rules govern whether the browser exposes the response; they do not establish that authentication or authorization is otherwise correctly configured. MDN explains CORS requests with credentials.

How to diagnose a CORS error

  1. Find the failing request. Open the browser’s developer tools, inspect the Network panel, and read the related console message for the specific CORS reason.
  2. Look for an OPTIONS request. If one appears before the intended request, inspect whether its response allows the required origin, method, and headers. If the preflight fails, the browser will not send the intended preflighted operation.
  3. Check whether the intended request was sent. If it was, do not infer from the CORS error that the server did not execute it. Check server logs and application behavior where you have access.
  4. If you control the endpoint, allow only what is needed. Configure the server to permit the required origins and resources rather than opening access more broadly than necessary. MDN documents the origin header and its use.
  5. If you do not control the remote server, consider a controlled proxy. A server you operate can make the request on your application’s behalf, but that creates a server-side dependency and needs appropriate access controls. MDN discusses the missing allow-origin error.

Why no-cors usually does not fix it

Setting mode: "no-cors" does not make a blocked API response readable. It produces an opaque response: JavaScript cannot inspect its status, headers, or body. Use it only when an opaque response is acceptable. MDN’s CORS error guidance explains this limitation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can you avoid a preflight?

Sometimes a request can be restructured to use a simpler method, safelisted headers, and an eligible content type, avoiding a preflight. That is appropriate only when the simpler request still correctly represents the operation. It does not change the server’s CORS policy: if the response is not permitted for the requesting origin, the browser can still withhold it from JavaScript. MDN describes simple requests.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.