REST Calls Across HNSCs (CORS)

First of all, what is CORS? It stands for Cross-Origin Resource Sharing, and if your eyes have already glazed over a little, don’t worry; it really isn’t that complicated. Say you have a site collection at, and it has some JavaScript that wants to load something from The thing on is a cross-origin resource (or CORS), because is an origin and is a different origin. Now the origin is just the part of the URL up to the fully qualified host name (and port if a non-standard port is used), so and are NOT cross-origin resources, they both have the same origin of

