FrontendBackend

CORS

Also written as Cross-Origin Resource Sharing

A browser security rule that blocks a webpage from calling an API on a different domain unless that API explicitly allows it — one of the first real bugs a frontend/backend pair hits when wiring two services together.

Think of it like

Like a bouncer who only lets in guests whose name is on a list the host provided in advance.

Junior or senior?

Junior sounds like

Googles the error and pastes a wildcard fix without understanding it.

Senior sounds like

Can explain why the restriction exists and configured allowed origins deliberately.

Ask them

“Have you had to configure CORS between a frontend and an API? What did you actually allow, and why?”

Sounds like real experience

Describes setting specific allowed origins or methods for a real integration, and explains the security reason the restriction exists.

Probe further if

Says they 'fixed CORS' by disabling it or allowing all origins with a wildcard, with no sense of why the restriction was there.