Easy Browser Question 27 of 229

What is CORS and why do API calls fail in the browser?

Frontend Master · Speak this in 60–90 seconds · Faridabad & Delhi NCR

PICTURE THIS: BROWSER VS ATTACKER

Bad inputScript / forged request
If unsanitizedRuns as the user
FixEscape, tokens, SameSite

Simple meaning

Browsers block a page on one origin from reading responses from another origin unless the server sends Access-Control-Allow-Origin.

1

WHY — Browser instead of guessing?

Why interviewers care about Browser:

Browser questions separate people

who only read docs from people who shipped.

Keep it short, concrete,

and tied to Frontend work.

Stay structured

Name the idea, why it exists, then one short example.

Close cleanly

End with when you use it and one common pitfall.

2

STEPS — What happens step by step?

Before you speak the answer, walk the interviewer through these steps:

  1. 1
    Browsers block a page

    on one origin from reading responses from another origin unless the server sends Access-Control-Allow-Origin.

  2. 2
    The API can still

    work in Postman because that tool is not a browser.

  3. 3
    The fix is server

    headers or a same-origin proxy, not a frontend hack.

  4. 4
    Give an example

    One tiny concrete case you can say aloud.

  5. 5
    Common mistake

    What juniors usually get wrong.

  6. 6
    Close

    When you pick this over the alternative.

3

EXAMPLE — See it in action

Here's a short line you can speak, broken into clear beats:

Say this line
“The API can still work in Postman because that tool is not a browser.”
Break into beats
TheAPIcanstillworkin
Speaking order
2987408337471632900

Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.

Key takeaway

Browsers block a page on one origin from reading responses from another origin unless the server sends Access-Control-Allow-Origin. The API can still work in Postman because that tool is not a browser.

Chat with us