Building a sound foundation
Resolving TLS issues
Preventing information disclosure
Setting HTTP security headers
Using CORS
MDN Web docs: Cross-Origin Resource Sharing (CORS)
MDN Web docs: Access-Control-Allow-Origin
How to Set Access-Control-Allow-Origin (CORS) Headers in Apache