cors vs csp
CORS allows a resource server to manage what sites can read its site data.
(server -> clients [site])
* on header of resource response
CSP prevents a site from loading (malicious) content. Many layers available.
(client [site] -> servers)
* on site's initial response headers