CORS
Also written as Cross-Origin Resource Sharing
A browser security rule that blocks a webpage from calling an API on a different domain unless that API explicitly allows it — one of the first real bugs a frontend/backend pair hits when wiring two services together.
Think of it like
Like a bouncer who only lets in guests whose name is on a list the host provided in advance.
Junior or senior?
Junior sounds like
Googles the error and pastes a wildcard fix without understanding it.
Senior sounds like
Can explain why the restriction exists and configured allowed origins deliberately.
Ask them
“Have you had to configure CORS between a frontend and an API? What did you actually allow, and why?”
Sounds like real experience
Describes setting specific allowed origins or methods for a real integration, and explains the security reason the restriction exists.
Probe further if
Says they 'fixed CORS' by disabling it or allowing all origins with a wildcard, with no sense of why the restriction was there.