Authentication & security

CORS

Cross-Origin Resource Sharing, or CORS, is a browser mechanism that uses HTTP response headers to control whether scripts may read responses from another origin.

Also found under: Cross-Origin Resource Sharing, Origin

How it works

An origin combines scheme, host and port, so local frontend and backend ports can be different origins. CORS is not user authentication and does not block arbitrary non-browser callers. WebSocket origin validation is related to browser security but is separate from the normal fetch CORS flow.

In a Pubb integration

A frontend calling your channel authorization endpoint may need CORS and credential settings when that endpoint lives on another origin. Those settings never justify sending the Pubb app secret directly from the browser.

Understand channel access

A practical example

A frontend on app.example.com calls an auth endpoint on api.example.com. Configure allowed origins and session handling, then perform the same server-side channel permission check.