Web appOpen in Telegram

Thread👋 Hello web developers!

9 messages · –
N
👋 Hello web developers! I was checking an external website that uses JavaScript fetch() to retrieve some data and then makes a POST request directly to an external API service. While inspecting the request in the browser’s Network → Headers tab, I noticed that when the request originates from example.com, the headers contain something like: Origin: https://example.com Referer: https://example.com/... The external API then accepts the request and returns a response successfully. ✅ However, when I copy the same API URL and try to send a POST request to it from my own Python script & with api_dog with different/same data, the request fails with: { "error": "Forbidden", "message": "Origin is not allowed" } From what I understand, the external API server is checking the Origin (and possibly Referer) header and only allowing requests coming from example.com. i found in the tab it was CORS problem when i do request externally? Is there a legitimate way to make the same API request from a Python backend/script? If the API requires requests to come from example.com, what exactly is the server validating — the Origin header, Referer, cookies, authentication, or something else? What should I look for in the browser’s Network tab to understand why the browser request succeeds while my Python request is rejected? I’m trying to understand how this works from a web-development perspective and what the correct approach would be. 🙏 Thanks! Edited Below :- will this doing changing the refere/origin is illegal in what way? police can caught or what
  1. J
    Yes police can catch & detain you
  2. S
    You simply have to use the right headers and body structure.
  3. も
    Example: Access-Control-Allow-Origin: https://example.com (Permits only this site) Example: Access-Control-Allow-Origin: * (Wildcard allows any site; unsafe for credentialed requests)
OOfftopicOfftopic@pythonofftopic · group · Tech
10 946members117writing in 30 days
Venue feed Open in Telegram

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count