Zum Hauptinhalt springen
Support
0
Kontaktieren Sie uns
English
Nederlands
Español
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareers
Cloud Compute

Mit Cloud Compute haben Sie jederzeit und überall Zugriff auf ein Portal, über das Sie Ihre gesamte IT-Umgebung konfigurieren können – egal wo auf der Welt Sie sich befinden.

Cloud-Speicher

Zuverlässiger Zugriff auf Ihre Dateien, Infrastruktur und Anwendungen zu jeder Zeit – ganz ohne Unterbrechungen oder Verzögerungen. Bei Worldstream bieten wir eine Vielzahl von Speicherlösungen an.

Flexible cloud icon
Flexible Cloud
Private cloud icon
Private Cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Objektspeicher
Hollow cube icon
Dateiablage
Block storage icon
Blockspeicher
Backup storage icon
Sicherungsspeicher
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Dedicated Server

Wählen Sie jetzt Ihren Dedicated Server. Individuelle oder Instant Delivery. Leistungsstarke Server, die perfekt zu Ihrem Anwendungsfall passen.

Use Cases

Ganz gleich, welcher Use Case – wir helfen Ihnen, die ideale Lösung zu finden.

Deal servers icon
Deals
AMD servers icon
AMD-Prozessoren
AI servers icon
Intel-Prozessoren
Hollow cube icon
Virtualisierung, Containerisierung & Orchestrierung
Hollow cube icon
Websites & Applications
Hollow cube icon
Gaming & Streaming Infrastruktur
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Smartes Outsourcing

Bestimmte IT-Lösungen generieren Mehrwert, andere erfüllen eher eine unterstützende Funktion. Denken Sie beim Outsourcing daran.

Kosteneffizienz

IT-Komplettpakete mögen erstmal wie eine sichere Option erscheinen, doch wenn man sich die Kosten genau anschaut, sind andere Lösungen oft sinnvoller.

IT-Flexibilität und Kontrolle

Outsourcing heißt nicht, dass man die Kontrolle verliert; man bekommt sogar mehr Flexibilität und Kontrolle.

Cloud-Repatriierung

Die Cloud ist kein Endziel: Sie sollten Ihre Cloud-Umgebung kontinuierlich prüfen und an die sich ändernden Anforderungen anpassen.

Finanzdienstleistungen
Logistik und Transport
Einzelhandel und E-commerce
Medien und Unterhaltung
Technik und Softwareentwicklung
Sicherheit
Managed Service Provider
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Chatten Sie mit unsKontaktieren Sie uns
Über WorldstreamÜber die TechnologieKundenfälleWissensdatenbank
Über unsLernen Sie unser Team kennenJobsWerden Sie WiederverkäuferZertifizierungenUnsere RechenzentrenUnser NetzwerkDDoS-SchutzAMD EPYC-ServerTechnologiepartnerBetriebssystemeAlle KundenfälleEasyTerraDutch Drone CompanyPerfGridArtikelFAQNachrichten und BlogbeiträgeProdukte und Services
Kontaktieren Sie uns

Rufen Sie an unter +31 (0) 174 – 712 117 Industriestraat 53, Naaldwijk

English
Nederlands
Español
0
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareersÜber WorldstreamÜber die TechnologieKundenfälleWissensdatenbankMy Worldstream
Contact
Support
EnglishNederlandsEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. CORS explained: why cross-origin requests get blocked

CORS explained: why cross-origin requests get blocked

Gilt für Web applications, APIs, browser-based clientsZielgruppe DeveloperZuletzt geprüft September 2026

Kort antwoord

CORS (Cross-Origin Resource Sharing) is a browser security mechanism, not a server or firewall feature. It blocks a web page on one origin from making requests to a different origin unless that other origin explicitly allows it through response headers. If your frontend works fine when you test the API with curl but breaks in the browser console, this is almost always why.

Auf dieser Seite
  • What counts as an "origin"
  • Why this exists
  • The symptom developers hit constantly
  • The fix, conceptually
  • What CORS does not protect

What counts as an "origin"

An origin is the combination of scheme, domain and port a page was loaded from. https://app.example.com and https://api.example.com are different origins even though they share a parent domain. So are http://example.com and https://example.com, because the scheme differs. Any time JavaScript running on one origin tries to call a URL on a different origin, that's a cross-origin request, and the browser gets involved.

Why this exists

Browsers enforce a same-origin policy by default: a script can freely call back to the origin it was loaded from, but calling a different origin is restricted unless that origin says it's fine. The reason is about protecting the user, not the server making the request. Without this restriction, a malicious site you visit could run JavaScript that silently sends requests to your bank, your email provider, or any other site you're logged into, riding on the session cookies your browser already holds for those sites. CORS is what stops a page you didn't intend to trust from quietly acting on your behalf against a site you do trust.

The symptom developers hit constantly

This is the pattern almost everyone runs into eventually: a frontend hosted on one domain calls an API hosted on a different domain. The API itself works perfectly when tested directly, with curl, Postman, or a REST client, because none of those are browsers and none of them enforce CORS. But the exact same request made from JavaScript in the browser fails, and the browser's console shows a CORS error rather than a network error. The request often did reach the server and the server often did respond. The browser just refused to hand that response to the page's JavaScript, because the API's server never sent back the headers needed to say "this origin is allowed to read my response".

The fix, conceptually

CORS is fixed on the server being called, not on the frontend making the call. The API needs to include an Access-Control-Allow-Origin header in its response, naming the origin (or origins) that are permitted to read that response. Depending on what the request needs to do, related headers cover which HTTP methods are allowed (Access-Control-Allow-Methods), which custom headers can be sent (Access-Control-Allow-Headers), and whether credentials like cookies can be included (Access-Control-Allow-Credentials). For anything beyond a simple GET request, the browser typically sends a preflight OPTIONS request first, asking the server to confirm the actual request would be allowed before sending it for real.

What CORS does not protect

It's worth being precise about what CORS actually is: a rule enforced by browsers, for browsers. It does nothing to stop a script, a server-to-server integration, or a tool like curl from calling an API directly, because none of those enforce the same-origin policy in the first place. An API that's meant to be publicly reachable is just as reachable with or without CORS headers set, from anything that isn't a browser reading a cross-origin response. If an API needs to restrict who can call it at all, that's a job for authentication, API keys, or IP allowlisting, not CORS.

Related articles

  • Using the Worldstream API
  • Common API automation recipes
War dieser Artikel hilfreich?

Solide IT. Keine Überraschungen

Sparringspartner für IT-Reife
Wir räumen die Hindernisse aus dem Weg, damit Sie freie Bahn haben
Vorhersehbare und transparente Kosten

Kontakt

  • Industriestraat 53, Naaldwijk
  • Zahlungsmöglichkeiten
  • Missbrauch
  • Ressourcen für Entwickler
  • Network Operations Center
  • Über uns
  • Lernen Sie unser Team kennen
  • Jobs
  • Werden Sie Wiederverkäufer
  • Zertifizierungen
  • Unsere Rechenzentren
  • Unser Netzwerk
  • DDoS-Schutz
  • AMD EPYC-Server
  • Technologiepartner
  • Betriebssysteme
  • Übersicht
  • FAQ
  • Kundenfälle
  • Nachrichten und Blogbeiträge
  • Use Cases
English
Nederlands
Español
English
Nederlands
Español
  • Rechtliches
  • Transparenzhinweis