Origin means scheme, host and port together
An origin is the combination of protocol, hostname and port, and changing any one of them makes it a different origin.
So HTTP and HTTPS versions of the same site are separate origins, and so are two ports on the same host. It is a precise definition that people apply loosely, which leads to sharing assumptions between things the browser treats as entirely unrelated.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
