25.13Cross-Origin Resource Sharing (CORS)


The Cross-Origin Resource Sharing (CORS) configuration category includes the following configurable options:

  • CORS Enabled

  • CORS Origins

25.13.1Property: CORS Enabled

Property Name CORS Enabled
Property Type BOOLEAN
Description Should this endpoint allow the use of CORS? Enable this item only if you understand what it is doing.
Default Value false
module.[MODULE_ID].config.cors.enable = false

25.13.2Property: CORS Origins

Property Name CORS Origins
Property Type STRING
Description A comma-separated list of allowable origins for the CORS filter. For example: https://example.com, https://try.smilecdr.com:9201. You may also use the wildcard value * to allow CORS for all domains, however this is generally not considered a good practice for production systems serving sensitive data.
Default Value *
module.[MODULE_ID].config.cors.origins = *
