Skip to main content

ALLOWED_ORIGINS

Constant ALLOWED_ORIGINS 

Source
pub const ALLOWED_ORIGINS: &str = "ALLOWED_ORIGINS";
Expand description

Name of the Worker variable listing extra origins that may call the app from a browser.

Comma-separated; spaces and a trailing / are ignored and invalid entries skipped. Listed origins get CORS headers (methods GET, POST, PUT, PATCH, DELETE; headers Content-Type, Authorization, Accept; credentials allowed) and pass the CSRF check. When the variable is unset or empty, serve adds no CORS layer and only same-origin browser requests may change data. Read once per request by serve; no binding call.

// worker.env in cloudflare.config.ts
ALLOWED_ORIGINS: bindings.text("https://app.example.com, https://admin.example.com"),

ยงExamples

use axum::extract::State;
use ocre::{ALLOWED_ORIGINS, Ctx, Result};

async fn origins(State(ctx): State<Ctx>) -> Result<String> {
    Ok(ctx.env().var(ALLOWED_ORIGINS).map(|v| v.to_string()).unwrap_or_default())
}