CORS for a Browser Client With Cookies
Configure CORS for a browser app on one origin that calls an API on another and sends a cookie. Do not copy a wildcard snippet. ORIGINS App: [ORIGIN] API: [ORIGIN] Cookie: [NAME, SAME-SITE PLAN] Methods: [LIST] Headers the browser will send: [LIST] DELIVER 1) The exact allowlist. Echo the request origin only if it is in the list. Never Access-Control-Allow-Origin: * together with credentials. 2) Allow-Credentials, the allowed methods and headers, and max-age for the preflight. 3) The cookie attributes that can work cross-site (SameSite=None; Secure) and the warning that this is a broader cookie. Prefer a same-site setup if I can change the domains, and say when that is the better design. 4) What CSRF means once a cookie is sent cross-site, and the control we pair with it (a token, or a same-site cookie plus a custom header). 5) A failing test: an origin not on the list gets no allow header. Do not reflect the Origin header unconditionally. Do not add CORS to "fix" a mobile app that is not a browser.
🌟 Example Output / Preview
Prompt Metadata
Primary Use Cases:
- •Legacy code modernization & technical refactoring
- •Full-stack layout generation & component structuring
- •CI/CD workflow automation & unit/E2E testing suites
Associated Tags:
💡 Pro Tips & Advice
1. Use bracketed items: Be sure to fill out all [PLACEHOLDER] elements with specific details before sending the prompt to the AI model.
2. Adjust temperature: For creative tasks, set AI temperature higher (e.g., 0.8), or lower (e.g., 0.2) for strict coding/technical tasks.
🔗 Related AI Prompts
Full SaaS Landing Page Build Spec (SEO + Conversion)
You are a Staff Product Designer + Frontend Engineer + SEO strategist. Build a complete, production-ready marketing landing page f...
SaaS Analytics Dashboard Full Build Spec
You are a Principal Product Designer + Frontend Lead. Design and specify a complete [LIGHT | DARK] analytics dashboard for [PRODUC...
SaaS Admin Panel Dashboard Build Spec
Design a full internal Admin Dashboard for [PRODUCT_NAME] used by [ADMIN_ROLE: support | ops | super-admin]. --- 🎯 CONTEXT Adm...