CORS relaxes browser reading rules, not authentication
CORS lets a server say which other origins may read its responses. It does not decide who may make the request.
The request is frequently sent regardless; what CORS controls is whether the calling page is allowed to see the answer. Treating it as an access control, rather than as a relaxation of a browser restriction, leads to servers that rely on it for authorisation and should not.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
- Clickjacking hides the real control beneath the clickPressed here. Answered there
