Same-Origin Habits
Same-Origin Habits: free step-by-step lesson with examples, common mistakes, and interview tips — part of jQuery Tutorial on Toolliyo Academy.
On this page
jQuery Tutorial · Lesson 69 of 100
Same-Origin Habits
Setup & DOM ✓ → Events Effects AJAX ✓ → Perf & Integrate → Ship & Projects
Perf & Integrate · 3 — Harden · ~10 min · Performance and Security
What is this?
Same-origin means same scheme, host, and port. Cookies and classic session auth work easily there. Cross-origin calls need CORS and careful credential settings.
Why should you care?
QueryVerse should prefer relative /api URLs on the app host instead of hard-coded third-party hosts for private data.
See it live — copy this example
Examples include the jQuery 3.7 CDN. Paste into an HTML file or use Run Example to preview.
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>QueryVerse</title>
<style>
body { font-family: system-ui, sans-serif; margin: 1.25rem; }
.box { padding: .75rem; border: 1px solid #ccc; border-radius: 8px; margin: .5rem 0; }
.muted { color: #666; }
button { margin-right: .35rem; margin-top: .35rem; }
input, select, textarea { margin: .25rem 0; }
table { border-collapse: collapse; width: 100%; }
th, td { border: 1px solid #ddd; padding: .4rem .55rem; text-align: left; }
.hidden { display: none; }
.row-odd { background: #f7f7f7; }
.active { font-weight: 700; }
.toast { background: #111; color: #fff; padding: .5rem .75rem; border-radius: 6px; }
</style>
</head>
<body>
<button type="button" id="rel">Describe relative API</button>
<button type="button" id="cross">Describe cross-origin</button>
<pre id="out" class="box muted"></pre>
<script src="https://code.jquery.com/jquery-3.7.1.min.js"></script>
<script>
$(function () {
$('#rel').on('click', function () {
$('#out').text('Same-origin pattern:\n$.getJSON("/api/qv/notifications")\n· cookies send by default\n· CSRF header still required for mutating calls');
});
$('#cross').on('click', function () {
$('#out').text('Cross-origin pattern:\nNeeds Access-Control-* from server\n$.ajax({ xhrFields:{ withCredentials:true } }) only if designed\nPrefer BFF/proxy on your origin for private data');
});
});
</script>
</body>
</html>
Run Example »
Edit the code below and click Run to see the result in Toolliyo’s live editor.
What happened?
- file:// pages are opaque origins — demos may fail CORS.
- In ASP.NET, put APIs under the site and call relatively.
- Do not turn on withCredentials casually.
Practice next
- Read both descriptions.
- Rewrite a hard-coded URL to relative form.
- Check your app’s real origin in location.origin.
- Use a reverse proxy/BFF.
- Document allowed origins for public widgets.
Remember
Prefer same-origin /api. CORS is a server deal. Credentials need design.
Relative API calls
An Axis Bank QueryVerse portal must call /api on the same host for session cookies.
Outcome: Relative URLs keep auth simple and policy-aligned.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!