Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
How can I remove CORS restrictions?
Key takeaways
- CORS is enforced by browsers; you cannot delete it.
- The only legitimate ways to satisfy CORS are server - side headers, a same - origin proxy, or developer - only browser flags.
- Each method has concrete steps, trade - offs, and security implications.
Why can’t I simply remove CORS?
CORS is a browser - enforced security feature defined in the web standard, so it cannot be turned off from a web page. The browser blocks any cross - origin request unless the response includes the appropriate Access-Control-Allow-Origin header.
Which method lets me satisfy CORS when I control the server?
Add the correct CORS headers on the server response. For public data you can use Access-Control-Allow-Origin: *; for credentialed requests you must specify the exact origin and include Access-Control-Allow-Credentials: true.
HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://myapp.example
Access-Control-Allow-Credentials: true
Content-Type: application/json
Steps
- Open the server configuration (e.g., Express, Nginx, Apache).
- Insert the header lines shown above.
- Restart the server and verify with the browser console.
What if I don’t own the remote API?
Use a same - origin proxy that you control. The browser sees the request as same - origin, the proxy forwards it to the target, and adds permissive CORS headers to the response.
Example proxy with Node Express
const express = require('express');
const request = require('request');
const app = express();
app.use('/proxy', (req, res) => {
const url = req.query.url;
request({ url, json: true }, (err, resp, body) => {
if (err) return res.status(502).send('Bad gateway');
res.set('Access-Control-Allow-Origin', '*');
res.json(body);
});
});
app.listen(3000, () => console.log('Proxy running on http://localhost:3000'));
Considerations
- Adds latency and an extra point of failure.
- Must respect the target server’s terms of service.
- Does not work if the target blocks proxy traffic.
Are there browser - only shortcuts for development?
Yes, you can launch Chrome or Edge with the flag --disable-web-security or install a CORS - unblock extension. This disables the same - origin policy for that browser instance only.
chrome --disable-web-security --user-data-dir=/tmp/chrome-dev
Limitations
- Never use in production; it disables many protections and is blocked by corporate policies.
- Only works on the local machine where the flag is set.
When would JSONP or script - tag tricks help?
Older sites sometimes expose data via a <script> tag, which the browser loads without CORS checks. This works only for GET requests that return JavaScript - compatible payloads.
Example
<script src="https://example.com/data.js"></script>
Risks
- Exposes the site to XSS attacks.
- Modern APIs rarely support this pattern.
Bottom line
You cannot remove CORS; you must either configure the server to send proper headers, route the request through a same - origin proxy, or use insecure developer - only browser flags for local testing. Choose the approach that matches your control over the resource and your security requirements.
Related guides
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.