<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security |</title><link>https://minhnn-tiny.github.io/tags/security/</link><atom:link href="https://minhnn-tiny.github.io/tags/security/index.xml" rel="self" type="application/rss+xml"/><description>Security</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Sat, 10 Jan 2026 00:00:00 +0000</lastBuildDate><image><url>https://minhnn-tiny.github.io/media/icon_hu_702a800cd775dbac.png</url><title>Security</title><link>https://minhnn-tiny.github.io/tags/security/</link></image><item><title>CORS and S3: The Internet's 'Stranger Danger' Rule</title><link>https://minhnn-tiny.github.io/blogs/aws-cors/</link><pubDate>Sat, 10 Jan 2026 00:00:00 +0000</pubDate><guid>https://minhnn-tiny.github.io/blogs/aws-cors/</guid><description>&lt;p&gt;Hello fellow cloud explorers! 🚀&lt;/p&gt;
&lt;p&gt;Welcome back to &lt;strong&gt;AWS for Newbies&lt;/strong&gt;! Today, we are tackling a topic that sounds super boring but is actually a secret superhero protecting your internet life: &lt;strong&gt;CORS&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Have you ever tried to load an image or a font on your website, and it just refuses to show up, and your browser console yells something red and scary like this?&lt;/p&gt;
&lt;blockquote class="border-l-4 border-neutral-300 dark:border-neutral-600 pl-4 italic text-neutral-600 dark:text-neutral-400 my-6"&gt;
&lt;p&gt;&lt;em&gt;“Access to fetch at &amp;lsquo;&amp;hellip;&amp;rsquo; has been blocked by CORS policy”&lt;/em&gt; 😱&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let&amp;rsquo;s decode this mystery in a way even a 7-year-old can understand.&lt;/p&gt;
&lt;h2 id="the-golden-rule-stranger-danger-sop"&gt;The Golden Rule: &amp;ldquo;Stranger Danger&amp;rdquo; (SOP)&lt;/h2&gt;
&lt;p&gt;Before we understand CORS, we need to understand the rule it breaks.&lt;/p&gt;
&lt;p&gt;Imagine the internet is a giant neighborhood. Every website lives in its own &lt;strong&gt;House&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Your house address is your &lt;strong&gt;Origin&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;An origin looks like this: &lt;code&gt;https://&lt;/code&gt; + &lt;code&gt;my-awesome-site.com&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The web browser (like Chrome or Firefox) is your overprotective bodyguard. It has a strict rule called the &lt;strong&gt;Same-Origin Policy (SOP)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Here is how SOP works:&lt;/strong&gt;
Your browser says: &amp;ldquo;If you are in House A (&lt;code&gt;my-awesome-site.com&lt;/code&gt;), you can play with toys inside House A. But you are &lt;strong&gt;NOT allowed&lt;/strong&gt; to just reach into House B (&lt;code&gt;google.com&lt;/code&gt;) and grab their toys without asking.&amp;rdquo;&lt;/p&gt;
&lt;h3 id="why-do-we-need-this-rule-"&gt;Why do we need this rule? 🤔&lt;/h3&gt;
&lt;p&gt;Imagine you are logged into your online bank bank website. Then, you open a new tab and visit a malicious website, &lt;code&gt;super-evil-hackers.net&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Without the SOP rule, the evil website could secretly tell your browser: &lt;em&gt;&amp;ldquo;Hey, while you are logged into the bank in that other tab, send me $500!&amp;rdquo;&lt;/em&gt; The browser would do it because it trusts &lt;em&gt;you&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;SOP stops this. It stops &amp;ldquo;strangers&amp;rdquo; (different origins) from touching your private stuff in other tabs.&lt;/p&gt;
&lt;p&gt;Here is a diagram of the browser blocking a &amp;ldquo;stranger&amp;rdquo;:&lt;/p&gt;
&lt;div class="mermaid"&gt;flowchart LR
subgraph Browser
WebsiteA[🏠 Your Website&lt;br/&gt;(Origin A)]
EvilSite[😈 Evil Website&lt;br/&gt;(Origin B)]
end
Bank[🏦 Your Bank&lt;br/&gt;(Origin C)]
WebsiteA -- "Can access" --&gt; WebsiteA
EvilSite -- "❌ SOP BLOCKED! ❌&lt;br/&gt;Cannot touch Bank!" -.- &gt; Bank
style EvilSite fill:#ffe6e6,stroke:#ff0000
style Bank fill:#e6ffe6,stroke:#00aa00
&lt;/div&gt;
&lt;h3 id="enter-cors-the-permission-slip"&gt;Enter CORS: The &amp;ldquo;Permission Slip&amp;rdquo;&lt;/h3&gt;
&lt;p&gt;SOP is great for security, but sometimes it&amp;rsquo;s annoying.&lt;/p&gt;
&lt;p&gt;What if House A and House B are best friends? What if my-awesome-site.com needs to fetch a cool image stored on my-image-bucket.com?&lt;/p&gt;
&lt;p&gt;They are different origins, so the browser bodyguard says &amp;ldquo;NOPE!&amp;rdquo; 🛑&lt;/p&gt;
&lt;p&gt;This is where CORS comes in. It stands for Cross-Origin Resource Sharing.&lt;/p&gt;
&lt;p&gt;Here is how CORS works: CORS is like a Permission Slip signed by the parents.&lt;/p&gt;
&lt;p&gt;Your website (House A) tries to get an image from another server (House B).&lt;/p&gt;
&lt;p&gt;Your browser sees this and gets suspicious. Before handing over the image, the browser politely asks House B: &amp;ldquo;Excuse me, House A wants this image. Do they have permission?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;House B checks its rules. If it likes House A, it sends back a special &amp;ldquo;header&amp;rdquo; (the permission slip) that says: Access-Control-Allow-Origin: * (Everyone is okay!) or Access-Control-Allow-Origin:
(Only friends are okay!).&lt;/p&gt;
&lt;p&gt;The browser sees the slip and lets the image through. ✅&lt;/p&gt;
&lt;div class="mermaid"&gt;sequenceDiagram
participant Browser 🛡️
participant MySite as 🏠 My Website (Origin A)
participant OtherServer as 🏢 Other Server (Origin B)
Note over Browser, OtherServer: The CORS Handshake 🤝
MySite-&gt;&gt;Browser: I need data from Origin B!
Browser-&gt;&gt;OtherServer: 🗣️ "Hey, Origin A wants your data. Is that okay?"
alt Permission Granted
OtherServer--&gt;&gt;Browser: ✅ "Yes! Here is my Permission Slip header."
Browser--&gt;&gt;MySite: Okay, here is the data.
else Permission Denied
OtherServer--xBrowser: ❌ "NO. I don't know them."
Browser--xMySite: 🔥 CORS ERROR! Blocked.
end
&lt;/div&gt;
&lt;h2 id="the-sneaky-trick-browser-extensions-"&gt;The Sneaky Trick: Browser Extensions 🕵️‍♀️&lt;/h2&gt;
&lt;p&gt;You asked: How can a browser extension bypass CORS?&lt;/p&gt;
&lt;p&gt;Great question!&lt;/p&gt;
&lt;p&gt;Remember, SOP and CORS are rules enforced by the browser for regular web pages.&lt;/p&gt;
&lt;p&gt;A browser extension (like an AdBlocker or a password manager) doesn&amp;rsquo;t live on a web page. It lives inside the browser itself. It&amp;rsquo;s like giving someone the master keys to the house.&lt;/p&gt;
&lt;p&gt;Extensions have special privileges. They can tell the browser, &amp;ldquo;Shhh, ignore those rules for a second, I&amp;rsquo;m an administrator.&amp;rdquo; This allows them to make requests to any server they want, ignoring CORS completely.&lt;/p&gt;
&lt;h2 id="real-world-use-case-aws-s3-cors-"&gt;Real-World Use Case: AWS S3 CORS ☁️&lt;/h2&gt;
&lt;p&gt;This is the most common place newbies face this mistake!&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s say you built a beautiful website,
. You decide to store all your cat photos in an AWS S3 Bucket because it&amp;rsquo;s cheap and fast.&lt;/p&gt;
&lt;p&gt;Your S3 bucket gets its own address, like
.&lt;/p&gt;
&lt;p&gt;Uh oh! Do you see the problem?&lt;/p&gt;
&lt;p&gt;Your Website Origin: cool-cat-pics.com&lt;/p&gt;
&lt;p&gt;Your Bucket Origin: &amp;hellip;s3.amazonaws.com&lt;/p&gt;
&lt;p&gt;They are different! When your site tries to load the cat photos, the browser blocks them. Broken images everywhere. 😿&lt;/p&gt;
&lt;h2 id="the-fix"&gt;The Fix&lt;/h2&gt;
&lt;p&gt;You need to go into your AWS S3 console, find your bucket, go to the &amp;ldquo;Permissions&amp;rdquo; tab, and scroll down to CORS.&lt;/p&gt;
&lt;p&gt;You need to add a &amp;ldquo;Permission Slip&amp;rdquo; (a JSON configuration) telling the bucket it&amp;rsquo;s okay to talk to your website.&lt;/p&gt;
&lt;p&gt;It looks something like this (simplified):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;AllowedOrigins&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;[https://cool-cat-pics.com](https://cool-cat-pics.com)&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;AllowedMethods&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;GET&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;MaxAgeSeconds&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;3000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;AllowedHeaders&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;*&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This config tells S3: &amp;ldquo;If cool-cat-pics.com asks to GET a photo, say YES!&amp;rdquo;&lt;/p&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;SOP (Stranger Danger): The browser rule that stops different websites from talking to each other for security.&lt;/p&gt;
&lt;p&gt;CORS (Permission Slip): The way servers tell the browser it&amp;rsquo;s okay to break the SOP rule for specific friends.&lt;/p&gt;
&lt;p&gt;S3 Needs CORS: Because your bucket and your website are usually two different &amp;ldquo;houses&amp;rdquo; on the internet.&lt;/p&gt;
&lt;p&gt;Keep practicing, and don&amp;rsquo;t fear the red error messages! 🦸‍♂️🦸‍♀️&lt;/p&gt;</description></item></channel></rss>