Summary

Woohoo! You just learned how to enable cross-origin request sharing (CORS) in our Web API.

You learned about what CORS is and how it works.

Then you learned some configuration stuff in setting up allowed origins, HTTP methods, request headers, and response headers.

Finally, you learned about passing credentials in cross-origin requests and enabling CORS at different scope in Web API.

Hurray! That's it, folks! Now, we know how to secure our Web API by adopting apt security solutions from various techniques available in the market.

Get ASP.NET Web API Security Essentials now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.