Content Application Developer Manual / Version 2310

Table Of Contents Solution for the Same-Origin Policy Problem


This solution is built into the CoreMedia Blueprint workspace, so you may use it out of the box. The idea is to customize the same origin policy by setting the Access-Control-Allow-Origin HTTP header accordingly. The allowed origins can be configured via the properties cae.cors.allowed-origins-for-url-pattern[*].

cae.cors.allowed-origins-for-url-pattern[{path\:.*}]= \,

To fine-tune the configuration for Cross-Origin Resource Sharing (CORS), use the provided cae.cors configuration properties. See CaeHandlerServicesConfiguration#caeCorsConfigurations(CaeCorsConfigurationProperties,ObjectProvider), CaeCorsConfigurationProperties and Section 3.1.4, “CORS Properties” in Deployment Manual.

