Cross-Origin Resource Sharing (CORS)
What Barrion checks when it evaluates how your site handles requests from other websites.
Barrion checks how your site controls access from other websites. CORS (Cross-Origin Resource Sharing) is the browser mechanism that governs whether external websites can read your API responses. Misconfigured CORS can expose user data to websites they did not intend to share it with.
What Barrion Checks
Origin Access Control
Barrion checks whether your site restricts which external websites can access its responses. If your site allows any website to read its responses (using a wildcard policy), sensitive data returned by your API could be read by a malicious site the user happens to visit.
Severity: High
Credentialed Cross-Origin Access
Barrion checks whether your site allows other websites to make requests on behalf of your authenticated users. If this is enabled alongside an overly permissive origin policy, attackers can make authenticated requests to your API from any website.
Severity: High
CORS Headers Configuration
Barrion checks several additional CORS headers that affect how browsers cache and handle cross-origin requests, including allowed request headers, exposed response headers, and preflight caching. Issues here typically affect performance or can cause legitimate cross-origin requests to fail.
Severity: Low to Medium
Cross-Origin Isolation Headers
Barrion checks for advanced isolation headers (COEP, COOP, CORP) that provide protection against sophisticated browser-level attacks. These are best practice for high-security applications.
Severity: Low
What to Do
CORS is configured in your application or API layer. Share failing findings with your development team. The most important findings to address are those flagged as High severity: overly permissive origin policies on authenticated endpoints. Barrion's finding details include the specific headers detected to help your team make targeted changes.