Signed media, CORS, DRM and delivery boundaries
Learn to: distinguish entitlement, signed media, CORS and DRM.
Prerequisites: 13-case-protected
Independent security boundaries
On a narrow screen, swipe the diagram horizontally to keep its labels readable.
Mental model verified
Application authorization decides entitlement. A signed delivery capability authorizes media requests. CORS controls browser access to cross-origin responses. EME provides a browser interface to content decryption modules; DRM additionally needs correct packaging, keys and a license service.
[S17] [S32] [S33]Worked failure synthesis
The playlist returns 200 but its segments return 403 after token expiry: inspect delivery authorization, not UI rendering. Alternatively, requests may succeed at the server while browser CORS blocks access. Check redirects and every resource in the manifest graph, including encryption-key and caption requests where applicable.
[S21] [S33]Decision and trade-off synthesis
Use HTTPS and a constrained authorization design for private assets. Credentialed CORS requires specific allowed origins rather than wildcard. DRM imposes licensing and device-test complexity; choose it from rights requirements, not to conceal a publicly downloadable URL in JavaScript.
[S27] [S32] [S33]Pitfall → improvement synthesis
Do not send signing keys to the client or log playable bearer URLs in analytics. Token-bearing manifests/segments need a deliberate cache and validation policy. Validate access revocation/expiry, cross-tenant requests, key-system behavior and delivery headers with the actual CDN.
[S17] [S27] [S33]Check yourself: Does a restrictive CORS policy prevent someone using a non-browser HTTP client?
No. CORS is enforced by browsers. Entitlement must be checked on the authorized delivery path.