CORS Settings
Description
CORS Settings.
May be used by
Properties
Allowed Origins (
allowedOrigins) Description
A list of regular expressions for the origins allowed to execute cross domain requests ('preflight checks') to the REST API. If no origins are configured, the server will deny any CORS requests.
Note that if a TLS tunnel is terminated by a load balancer which connects to IAM via http, IAM will consider most requests as CORS requests unless 'Strict CORS Validation' is deactivated.
Attributes
RegEx-List
Optional
Strict CORS Validation (
strictCorsValidation) Description
Match the 'Origin' header of the browser exactly.
Disabling this flag allows Airlock IAM to be connected to e.g. a load-balancer without TLS (load-balancer terminates TLS):
- 'https://yourhost.com:443' is then considered a match compared to 'http://yourhost.com:80', and treated as same-origin
Note that this setting does not influence the 'Allowed Origins'.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)
type: CorsSettings
id: CorsSettings-xxxxxx
displayName:
comment:
properties:
allowedOrigins:
strictCorsValidation: true