QSCSCore HTTP API, CORS & OPTIONS
On this page 1 sections
CORS & OPTIONS
QSCS is permissive about cross-origin browser traffic to make the browser substrate, third-party dashboards, and your own JS apps straightforward. Every proxied response carries CORS headers, and OPTIONS preflight is answered without ever touching the upstream.
/*
Preflight handler. The daemon returns a 200 immediately.
Response headers
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET, POST, HEAD, OPTIONS
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Max-Age: 86400
Content-Length: 0Example
curl -i -X OPTIONS -H 'Origin: https://example.com' \
-H 'Access-Control-Request-Method: POST' \
http://node-eu1:8080/api/anythingHeaders injected into proxied responses
The same CORS triplet is folded into every upstream response and every HEADLESS response so a browser fetch from a different origin can always read the result.
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET, POST, HEAD, OPTIONS
Access-Control-Allow-Headers: Content-Type, AuthorizationTightening CORS. The current policy is wide open. If you need a stricter policy for a specific deployment, terminate TLS in front of QSCS (Caddy, nginx) and replace the headers there.