Skip to main content

CORS

When a user's browser requests a bucket, it declares the domain, request method, and headers in the request. Using Cross-Origin Resource Sharing (CORS) technology, you can restrict access to objects in a bucket based on the values of these parameters.

To use CORS, the technology must be supported by both the storage and the user's browser; CORS support is enabled by default in modern browsers.

For CORS to work, Virtual-Hosted addressing must be enabled.

You can set up the CORS configuration in the control panel or upload a configuration XML file via the S3 API.

CORS parameters

HeaderDescriptionRequired
AllowedOriginsList of domains from which requests to the bucket are allowed✓
AllowedHeadersHeaders available for use
in a JavaScript application in the browser✗
ExposeHeadersHeaders allowed in a request to an object✗
AllowedMethodsHTTP methods allowed for use in requests. Available methods: GET, PUT, HEAD, POST, DELETE✓
MaxAgeSecondsThe time, in seconds, for which Preflight request results can be cached (in seconds). If the header is not specified, the default value of 3600 is applied✗

Configure CORS

You can add up to 100 CORS rules.

  1. In the control panel, click Products on the top menu and select S3.
  2. Go to the Buckets section.
  3. Open the bucket page → CORS tab.
  4. Click Create Rule.
  5. Configure the CORS rule parameters.
  6. Optional: to add another rule, click Add Rule.
  7. Click Create.