Earlier quoted context omitted.
Again, CORS does not protect, the SOP does :-)
> Again, CORS does not protect, the SOP does :-) This is simply false. You are somehow wrongly assuming that only same-origin requests exist or are needed. This scenario never existed in the real world beyond the scope of small personal projects.
No they are not making that assumption.