Giving only necessary permissions.

System controlling network traffic based on rules.

Browser security policy controlling permitted content sources.

Obtaining higher permissions than intended.

Firewall designed to protect web applications.

Browser rule restricting cross-origin access.

Boundary separating resources with different trust levels.

Rules controlling network communication.

Mechanism controlling permitted cross-origin requests.

Point where security assumptions change.