CORS Preflight Caching Extends Cross-Origin Policy Decisions
CORS Preflight Caching Extends Cross-Origin Policy Decisions An API operator can remove a cross-origin method from its CORS configuration and still see browsers issue that method without a fresh OPTIONS exchange. The browser may already hold a valid preflight cache entry authorizing the request shape. Until that entry expires or is discarded, the earlier policy decision can continue to suppress a new preflight. This behavior does not make CORS authorization permanent, and it does not bypass the CORS check on the actual response. It does create an operational interval in which a server-side policy change and browser preflight behavior are not synchronized. Access-Control-Max-Age therefore affects more than request volume: it influences the lifetime of a cached permission decision inside the user agent.