---
title: "CORS, CSRF, and XSS: different threat models"
description: "How can you separate CORS, CSRF, and XSS threat models?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T02.09/"
topicId: "T02.09"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

How can you separate CORS, CSRF, and XSS threat models?

## What we will work through

Separate CORS, CSRF, and XSS threat models.

## Before you begin

Previously covered: How automatically sent credentials enable CSRF.

- [How automatically sent credentials enable CSRF](/en/articles/topics/T02.05/)
