FeatureFuel
14

Allow restricting the Access-Control-Allow-Origin header to a specific origin

Source: supabase/supabase#7038 · opened by @chipilov
It seems that Supabase currently handles CORS by using a wildcard for the Access-Control-Allow-Origin (i.e. any origin can send requests to a Supabase project).

I think it would be beneficial to allow restricting the access only to a specific origin via the settings in the Dashboard (similar to how redirects can be restricted to specific URLs in the Auth settings of the dashboard).

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests