ArchSetu
ArchSetu
ArchSetuToolsSecurityCORS Preflight Simulator
Free tool

CORS Preflight Simulator

Method, Content-Type, and headers, checked against the actual Fetch spec's CORS-safelisted request rules - not an approximation.

Method

Triggers a preflight OPTIONS request

  • Content-Type "application/json" isn't one of the three safelisted values (application/x-www-form-urlencoded, multipart/form-data, text/plain).
  • Header not safelisted: authorization (e.g. Authorization always triggers a preflight).

Was this tool helpful?

See this same kind of analysis applied to your whole repository

Call graphs, dead code, blast radius, and a health score. Results in 60 seconds, free.

Analyze a repository

Runs entirely in your browser. Nothing is stored. Free forever.

Powered by ArchSetu