👋 Hello web developers!
I was checking an external website that uses JavaScript fetch() to retrieve some data and then makes a POST request directly to an external API service.
While inspecting the request in the browser’s Network → Headers tab, I noticed that when the request originates from example.com, the headers contain something like:
Origin: https://example.com
Referer: https://example.com/...
The external API then accepts the request and returns a response successfully. ✅
However, when I copy the same API URL and try to send a POST request to it from my own Python script & with api_dog with different/same data, the request fails with:
{
"error": "Forbidden",
"message": "Origin is not allowed"
}
From what I understand, the external API server is checking the Origin (and possibly Referer) header and only allowing requests coming from example.com.
i found in the tab it was CORS problem when i do request externally?
Is there a legitimate way to make the same API request from a Python backend/script?
If the API requires requests to come from example.com, what exactly is the server validating — the Origin header, Referer, cookies, authentication, or something else?
What should I look for in the browser’s Network tab to understand why the browser request succeeds while my Python request is rejected?
I’m trying to understand how this works from a web-development perspective and what the correct approach would be. 🙏
Thanks!
Edited Below :-
will this doing changing the refere/origin is illegal in what way? police can caught or what
Thread👋 Hello web developers!
9 messages · –B N
J C D S も Example: Access-Control-Allow-Origin: https://example.com (Permits only this site) Example: Access-Control-Allow-Origin: * (Wildcard allows any site; unsafe for credentialed requests)D