Decides whether a page on the request's origin may read the answer.
Applies the module's four rules in order. It never refuses the request itself; it decides only whether CORS headers are sent.
the express request
preflight: true for an OPTIONS preflight, which is judged against the realm because it names no client
preflight: true
{ allowed, origin, code, why }, where code is the error code of a withheld decision about a cross-origin request, or empty
{ allowed, origin, code, why }
code
Decides whether a page on the request's origin may read the answer.
Applies the module's four rules in order. It never refuses the request itself; it decides only whether CORS headers are sent.