DeepFrontend
Learning Paths
Practice
System Design & DS
Design Studio
Data Structures Curriculum
Real-World Case Studies
Careers
Job Board
Resume Builder
Blog
Sign in
Search
⌘K
Go Pro
Loading compiler resources...
Web Security Quiz Practice
Active Recall Drill Session
← Exit Session
Question 1 of 1
medium
Web Security
What's a subtle risk of hand-rolling origin-matching logic instead of using a maintained CORS library?
A
There is no real risk either way
B
A naive check (e.g. substring matching) could incorrectly allow a similarly-named malicious origin, like evil-app.example.com matching an intended app.example.com allowlist entry
C
Hand-rolled logic is always faster
D
Libraries cannot express allowlists at all
Check Answer