Part 16 · Best practices

Signed media, CORS, DRM and delivery boundaries

Learn to: distinguish entitlement, signed media, CORS and DRM.

Prerequisites: 13-case-protected

Independent security boundaries

Each column answers a different question. The figure is a conceptual checklist rather than one linear transaction; DRM is optional and CORS is not authentication.
Each column answers a different question. The figure is a conceptual checklist rather than one linear transaction; DRM is optional and CORS is not authentication. [S17] [S21] [S27] [S32] [S33]

On a narrow screen, swipe the diagram horizontally to keep its labels readable.

Mental model verified

Application authorization decides entitlement. A signed delivery capability authorizes media requests. CORS controls browser access to cross-origin responses. EME provides a browser interface to content decryption modules; DRM additionally needs correct packaging, keys and a license service.

[S17] [S32] [S33]

Worked failure synthesis

The playlist returns 200 but its segments return 403 after token expiry: inspect delivery authorization, not UI rendering. Alternatively, requests may succeed at the server while browser CORS blocks access. Check redirects and every resource in the manifest graph, including encryption-key and caption requests where applicable.

[S21] [S33]

Decision and trade-off synthesis

Use HTTPS and a constrained authorization design for private assets. Credentialed CORS requires specific allowed origins rather than wildcard. DRM imposes licensing and device-test complexity; choose it from rights requirements, not to conceal a publicly downloadable URL in JavaScript.

[S27] [S32] [S33]

Pitfall → improvement synthesis

Do not send signing keys to the client or log playable bearer URLs in analytics. Token-bearing manifests/segments need a deliberate cache and validation policy. Validate access revocation/expiry, cross-tenant requests, key-system behavior and delivery headers with the actual CDN.

[S17] [S27] [S33]
Keep this: Separate authorization, cross-origin access, encryption and device compatibility.
Check yourself: Does a restrictive CORS policy prevent someone using a non-browser HTTP client?

No. CORS is enforced by browsers. Entitlement must be checked on the authorized delivery path.

Sources & further reading

  1. [S17] Secured video playback

    Mux · official documentation · accessed 2026-10-10

    Supports: Server-generated playback JWTs, token audience and expiration requirements.

    Read this page to inspect the API and assumptions behind the cited explanation.

  2. [S21] HLS.js README

    HLS.js maintainers · official documentation · accessed 2026-10-10 · current docs

    Supports: MSE-based HLS, native fallback, browser codec constraints and CORS on all HLS resources.

    Read this page to inspect the API and assumptions behind the cited explanation.

  3. [S27] dash.js DRM

    DASH Industry Forum · official documentation · accessed 2026-10-10 · current docs

    Supports: Protection data, EME key systems and license-server configuration.

    Read this page to inspect the API and assumptions behind the cited explanation.

  4. [S32] Encrypted Media Extensions API

    MDN · official documentation · accessed 2026-10-10

    Supports: Browser/CDM interface for protected playback; EME is not a complete content protection service.

    Read this page to inspect the API and assumptions behind the cited explanation.

  5. [S33] Cross-Origin Resource Sharing

    MDN · official documentation · accessed 2026-10-10

    Supports: Server response headers determine cross-origin access; credentialed requests cannot use wildcard origins.

    Read this page to inspect the API and assumptions behind the cited explanation.