CORS relaxes browser reading rules, not authentication

CORS lets a server say which other origins may read its responses. It does not decide who may make the request.

The request is frequently sent regardless; what CORS controls is whether the calling page is allowed to see the answer. Treating it as an access control, rather than as a relaxation of a browser restriction, leads to servers that rely on it for authorisation and should not.

More on Browser security