How to properly setup nginx Access-Control-Allow-Origin into response header based on the Origin header from the request? How to properly setup nginx Access-Control-Allow-Origin into response header based on the Origin header from the request? javascript javascript

How to properly setup nginx Access-Control-Allow-Origin into response header based on the Origin header from the request?

Using if can sometimes break other config such as try_files. You can end up with unexpected 404s.

Use map instead

map $http_origin $cors_header {    default "";    "~^https?://[^/]+\.example\.com(:[0-9]+)?$" "$http_origin";}server {    ...    location / {        add_header Access-Control-Allow-Origin $cors_header;        try_files $uri $uri/ /index.php;    }    ... }

If is evil

I'm starting to use this myself, and this is the line in my current Nginx configuration:

add_header 'Access-Control-Allow-Origin' "$http_origin";

This sets a header to allow the origin of the request as the only allowed origin. So where ever you are coming from is the only place allowed. So it shouldn't be much different than allowing "*" but it looks more specific from the browser's perspective.

Additionally you can use conditional logic in your Nginx config to specify a whitelist of hostnames to allow. Here's an example from

if ($http_origin ~* (whitelist\.address\.one|whitelist\.address\.two)$) {  add_header Access-Control-Allow-Origin "$http_origin";}

I plan to try this technique in my own server to whitelist the allowed domains.

Here is a part of a file from conf.f directory where people always describes their virtual hosts of Nginx.$http_origin compares with list of allowed_origins and then in second map block the system decides what will write to "header Access-Control-Allow-Origin" according to allowed list.Here is a part of code.

#cat /etc/nginx/conf.d/somehost.conf

map $http_origin $origin_allowed {        default 0; 1; 1;}map $origin_allowed $origin {        default "";        1 $http_origin;}    server {       server_name;    #...[skipped text]    add_header Access-Control-Allow-Origin $origin always;    #....[skipped text]}

I test it om my servers. All works fine.Have a nice day & be healthy,Eugene.