14
Allow restricting the Access-Control-Allow-Origin header to a specific origin
Source: supabase/supabase#7038 · opened by @chipilov
It seems that Supabase currently handles CORS by using a wildcard for the Access-Control-Allow-Origin (i.e. any origin can send requests to a Supabase project).
I think it would be beneficial to allow restricting the access only to a specific origin via the settings in the Dashboard (similar to how redirects can be restricted to specific URLs in the Auth settings of the dashboard).
I think it would be beneficial to allow restricting the access only to a specific origin via the settings in the Dashboard (similar to how redirects can be restricted to specific URLs in the Auth settings of the dashboard).
No pledges yet. Be the first to back this.
Comments
Similar requests
Allow Access-Control-Allow-Origin (CORS) policy to be set via dashboard
3 votes · 0 comments
Edge functions: regional invocation with an array of allowed regions
1 vote · 0 comments
CORS in supabase: Set Origin to server request
1 vote · 0 comments
Compression Issue with ‘application/vnd.pgrst.object+json’ Content-Type in PostgREST Responses
3 votes · 0 comments
Retrieve response headers
2 votes · 0 comments
No comments yet.