What is a CORS preflight request?
PICTURE THIS: A REST CALL
Simple meaning
For non-simple cross-origin calls, the browser first sends an OPTIONS request asking if the real method, headers, and origin are allowed.
WHY — HTTP instead of guessing?
Why interviewers care about HTTP:
who only read docs from people who shipped.
and tied to Full Stack work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1For non-simple cross-origin calls,
the browser first sends an OPTIONS request asking if the real method, headers, and origin are allowed.
- 2The API must answer
with Access-Control-Allow-* headers.
- 3If preflight fails, the
actual POST never leaves the browser.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
For non-simple cross-origin calls, the browser first sends an OPTIONS request asking if the real method, headers, and origin are allowed. The API must answer with Access-Control-Allow-* headers.