Enable CORS on an application
Add Response Phase rules that send CORS headers for GET, POST, and HEAD requests, for complex requests, or for a list of allowed origins.
You can enable Cross-Origin Resource Sharing (CORS) on an application from Azion Console, with Response Phase rules in Rules Engine for Applications. Each section creates one rule that adds CORS headers to the responses of the application.
CORS uses HTTP headers to grant a user agent access to resources on an origin server other than the current document’s. For example, an HTML page served by domain A requests a CSS stylesheet or a JavaScript file from domain B. For security reasons, most browsers block the cross-origin HTTP requests that scripts start. The CORS headers in a response tell the browser which of these requests to allow.
A request that uses GET, POST, or HEAD needs only the Access-Control-Allow-Origin header in the response. Any other request can be considered complex. So can a request that involves multiple parameters, headers, authentication, a request body, or another specialized configuration. A complex request needs additional headers.
Prerequisites
- An application that a workload delivers, with a rule that sends its requests to an origin. To create both, refer to Applications quickstart.
- Access to Azion Console. To sign in, refer to Access Azion Console.
Allow cross-origin GET, POST, and HEAD requests
The rule in this section adds Access-Control-Allow-Origin: * to the responses of every path that starts with /your-uri. The * value lets a page from any origin read those responses. Replace /your-uri with the path that receives the cross-origin requests.
To create the rule in Azion Console:
Access Azion Console > Applications > your application.
In the General section, enter GET/POST/HEAD CORS in Name.
In Description, enter Allows CORS for GET requests in /your-uri.
In the Phase section, select Response Phase. The phase of a rule cannot change after you create the rule.
In the Criteria section, select ${uri} as the variable and starts_with as the operator.
Enter /your-uri as the argument.
In the Behaviors section, select the behavior that adds a response header. The API names it add_response_header.
Enter Access-Control-Allow-Origin: * as the argument of the behavior.
The rule appears in the Rules Engine tab, under Response. The responses to paths that start with /your-uri carry Access-Control-Allow-Origin: *. For the format that a header argument takes, refer to Add Request Header.
Allow complex cross-origin requests
A complex request needs more headers than Access-Control-Allow-Origin. The rule in this section allows the OPTIONS method on paths that start with /your-uri. Its headers also cover GET, POST, and HEAD requests to those paths. The rule adds these five headers to each response:
To create the rule in Azion Console:
Access Azion Console > Applications > your application.
In the General section, enter OPTIONS CORS in Name.
In Description, enter Allows CORS for OPTIONS requests in /your-uri, as well as non-complex requests.
In the Phase section, select Response Phase. The phase of a rule cannot change after you create the rule.
In the Criteria section, select ${uri} as the variable and starts_with as the operator.
Enter /your-uri as the argument.
In the Behaviors section, select the behavior that adds a response header. The API names it add_response_header.
Enter Access-Control-Allow-Origin: * as the argument of the behavior.
For each remaining header in the list, select + Add Behavior. Select the same behavior, and enter the header as its argument.
The rule appears in the Rules Engine tab, under Response. The responses to paths that start with /your-uri carry the five headers.
To allow other request types, change the values of Allow, Access-Control-Allow-Methods, and Access-Control-Allow-Origin. To set the format of the response, add a Content-Type header to the same rule.
Allow cross-origin requests from specific origins
The rule in this section adds the CORS headers only when a request comes from one of three origins. It reads the Origin request header through the ${http_origin} variable, with one criterion per origin, joined by Or. Replace the three origins with the ones your application accepts:
A rule that allows specific origins requires Application Accelerator on the application.
To turn on Application Accelerator in Azion Console:
Access Azion Console > Applications > your application.
In the Modules section, turn on Application Accelerator.
The application runs with Application Accelerator on. Turning on a Product can generate usage-related costs. For more information, refer to Pricing.
The rule adds the same five headers as a rule for complex requests:
To create the rule in Azion Console:
Access Azion Console > Applications > your application, then select the Rules Engine tab.
In the General section, enter Multiple origins CORS in Name.
In the Phase section, select Response Phase. The phase of a rule cannot change after you create the rule.
In the Criteria section, select ${http_origin} as the variable and is_equal as the operator.
Enter http://www.example.com as the argument.
For each remaining origin, select Or. Select ${http_origin} and is_equal again, and enter the origin as the argument.
In the Behaviors section, select the behavior that adds a response header. The API names it add_response_header.
Enter Access-Control-Allow-Origin: * as the argument of the behavior.
For each remaining header in the list, select + Add Behavior. Select the same behavior, and enter the header as its argument.
The rule appears in the Rules Engine tab, under Response. A response carries the five headers only when the Origin header of its request matches one of the three origins exactly. For how criteria combine with And and Or, refer to Conditionals.