Discussion on: ✋🏼🔥 CS Visualized: CORS

Lydia Hallie

Origin is actually a "forbidden header", you can't manually set it! 😊 We can't fake the Origin header that way.

However, making the exact same request outside a browser (eg. cURL) would give you access to the resources!