0Pricing
OAuth2 & OpenID Connect Deep Dive · Ders

Kökenler Arası Kaynak Paylaşımı (CORS)

Özellikle korunan kaynaklara erişen tek sayfalı uygulamalar bağlamında OAuth2 ve OIDC içindeki CORS ilkelerini anlayın.

Kökenler Arası Kaynak Paylaşımı (CORS), CoddyKit'te ücretsiz bir OAuth2 & OpenID Connect Deep Dive dersidir. Bu, 4 dersinin 2. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, OAuth2 & OpenID Connect Deep Dive öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

CORS & Secure Web Apps

Welcome! Today we'll explore Cross-Origin Resource Sharing (CORS), a crucial security feature for modern web applications.

CORS allows web browsers to securely handle requests between a client-side application (like a Single-Page Application, SPA) and an API server when they're on different domains.

This is especially vital when your SPA uses OAuth2 or OpenID Connect to access protected resources.

The Same-Origin Policy

To understand CORS, we first need to know about the Same-Origin Policy (SOP).

  • SOP is a fundamental browser security feature.
  • It prevents web pages from making requests to a different domain than the one that served the page.
  • For example, a script from app.example.com cannot directly make an AJAX request to api.anothersite.com.

This protects users from malicious scripts trying to steal data from other sites you're logged into.

Why CORS is Needed

While SOP is great for security, it creates a problem for modern web architectures.

Many applications, especially SPAs, need to fetch data from APIs hosted on a different domain or port. For instance:

  • Your SPA is at https://my-app.com
  • Your API is at https://api.my-app.com
  • Your OAuth2 Authorization Server is at https://auth.my-app.com

CORS provides a controlled way to relax the SOP, allowing these cross-origin requests while maintaining security.

Simple CORS Requests

Some cross-origin requests are considered 'simple' by browsers. These don't trigger a special preflight check.

A request is simple if it meets all these conditions:

  • Method is GET, HEAD, or POST.
  • Only specific allowed headers (e.g., Accept, Accept-Language, Content-Language, Content-Type).
  • Content-Type header is limited to application/x-www-form-urlencoded, multipart/form-data, or text/plain.

If simple, the browser sends the request directly, and the server includes CORS headers in its response.

Preflight for Complex Requests

Most requests in modern SPAs, especially those involving OAuth2 tokens, are not simple.

A 'complex' request requires a browser to send a 'preflight' OPTIONS request before the actual request:

  • Methods: PUT, DELETE, or custom methods.
  • Headers: Custom headers (like Authorization for access tokens).
  • Content-Type: application/json (common for APIs).

The server must respond to this OPTIONS request with appropriate CORS headers, indicating if the actual request is allowed.

Key CORS Response Headers

The server communicates its CORS policy through specific HTTP response headers:

  • Access-Control-Allow-Origin: Specifies which origins are allowed to access the resource. Can be * (wildcard, generally discouraged for security) or a specific origin like https://my-app.com.
  • Access-Control-Allow-Methods: Lists the HTTP methods (e.g., GET, POST, PUT, DELETE) allowed for the resource.
  • Access-Control-Allow-Headers: Indicates which HTTP headers (e.g., Authorization, Content-Type) are allowed in the actual request.

These headers are crucial for the browser to permit the cross-origin request.

CORS & Credentials

The Access-Control-Allow-Credentials header is another important CORS header.

When set to true, it tells the browser that the server permits cookies, HTTP authentication, or client-side SSL certificates to be included with the cross-origin request.

For OAuth2/OIDC, access tokens are typically sent in the Authorization header, not as cookies. However, if you're using session cookies for authentication or identity management alongside tokens, this header becomes relevant.

CORS in OAuth2/OIDC Flows

CORS is essential at several points in OAuth2/OIDC:

  • Token Exchange: Your SPA might need to exchange an authorization code for an access token at the Authorization Server's token endpoint. This is a cross-origin POST request.
  • API Access: Once your SPA has an access token, it uses it to call a Resource Server's API (e.g., GET /userinfo, POST /orders). This is also a cross-origin request.

The Authorization Server and Resource Server must be configured correctly to allow these requests from your SPA's origin.

Best Practices for CORS

To ensure secure OAuth2/OIDC implementations with CORS:

  • Specific Origins: Always specify exact origins (e.g., https://my-app.com) in Access-Control-Allow-Origin, never use * in production.
  • Limit Methods & Headers: Only allow the HTTP methods and headers that your client applications genuinely need.
  • Configure Servers: Ensure your Authorization Server and Resource Server are correctly configured to send the necessary CORS headers.
  • Handle Preflights: Make sure your server can respond to OPTIONS requests for preflight checks.

Misconfigured CORS can lead to security vulnerabilities, allowing unauthorized access.

CORS Configuration Check

Your SPA at https://my-app.com needs to make a POST request with an Authorization header and Content-Type: application/json to your API at https://api.my-app.com/data. Which CORS response headers should the API server include to allow this?

Recap: CORS & Security

You've learned about Cross-Origin Resource Sharing (CORS) and its vital role in securing modern web applications, especially those leveraging OAuth2 and OpenID Connect.

  • CORS relaxes the browser's Same-Origin Policy.
  • It enables secure communication between different origins.
  • Preflight requests for 'complex' API calls are common with OAuth2 tokens.
  • Proper server-side configuration of CORS headers (Access-Control-Allow-Origin, Access-Control-Allow-Methods, Access-Control-Allow-Headers) is key.

Always follow best practices to prevent misconfigurations that could expose your protected resources.

Sıkça Sorulan Sorular

“Kökenler Arası Kaynak Paylaşımı (CORS)” dersi ücretsiz mi?

Evet — “Kökenler Arası Kaynak Paylaşımı (CORS)” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve OAuth2 & OpenID Connect Deep Dive kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.

“Kökenler Arası Kaynak Paylaşımı (CORS)” dersinde ne öğreneceğim?

Özellikle korunan kaynaklara erişen tek sayfalı uygulamalar bağlamında OAuth2 ve OIDC içindeki CORS ilkelerini anlayın. OAuth2 & OpenID Connect Deep Dive ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

OAuth2 & OpenID Connect Deep Dive öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te OAuth2 & OpenID Connect Deep Dive, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 2. dersidir.

“Kökenler Arası Kaynak Paylaşımı (CORS)” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu OAuth2 & OpenID Connect Deep Dive dersinde kod yazıp çalıştırabilir miyim?

Evet. Her OAuth2 & OpenID Connect Deep Dive dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Onay ve Kullanıcı Deneyimi
  2. Kökenler Arası Kaynak Paylaşımı (CORS)
  3. Ön Kanal ve Arka Kanal Oturum Kapatma
  4. mTLS ile Gönderici Kısıtlı Belirteçler
← OAuth2 & OpenID Connect Deep Dive Sayfasına Dön