Skip to content
CORSAKRONIMY
AcronymsAbbreviations everyone uses and few explain

CORS

Cross-Origin Resource Sharing

A browser mechanism that controls whether a webpage from one domain can call an API on another domain. It is configured using HTTP headers; overly permissive rules can weaken security.

Why it matters

Protects users from third-party websites silently calling your API from their browsers. Well-configured rules allow only your own domains to access the API.

What's missing without it

Overly permissive CORS rules allow any website to query the API of an authenticated user — data leaks without any server breach.

When it is used

Whenever an API is called from a browser, especially when the dashboard and API are hosted on different domains.

How we use it

A dashboard at app.nazwa-domeny.pl receives permission to call the API at api.nazwa-domeny.pl — without this permission, the browser will block the response.

Numbers worth knowing

CORS in data

78 600 000 000

gemiusAdReal, badanie cross-mediowe rynku reklamowego w Polsce, sierpień 2026

Gemius09/2026Poland