Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.
The question
How can you separate CORS, CSRF, and XSS threat models?
What we will work through
Separate CORS, CSRF, and XSS threat models.
Before you begin
Previously covered: How automatically sent credentials enable CSRF.