DocumentationBuild. Deploy. Operate.
DocsQSCSCore HTTP API

QSCSCore HTTP API, CORS & OPTIONS

On this page 1 sections

CORS & OPTIONS

QSCS is permissive about cross-origin browser traffic to make the browser substrate, third-party dashboards, and your own JS apps straightforward. Every proxied response carries CORS headers, and OPTIONS preflight is answered without ever touching the upstream.

OPTIONS /*

Preflight handler. The daemon returns a 200 immediately.

Response headers

HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET, POST, HEAD, OPTIONS
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Max-Age: 86400
Content-Length: 0

Example

curl -i -X OPTIONS -H 'Origin: https://example.com' \
  -H 'Access-Control-Request-Method: POST' \
  http://node-eu1:8080/api/anything

Headers injected into proxied responses

The same CORS triplet is folded into every upstream response and every HEADLESS response so a browser fetch from a different origin can always read the result.

Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET, POST, HEAD, OPTIONS
Access-Control-Allow-Headers: Content-Type, Authorization
Tightening CORS. The current policy is wide open. If you need a stricter policy for a specific deployment, terminate TLS in front of QSCS (Caddy, nginx) and replace the headers there.
Need a hand with your deployment?Contact support ↗Back to top ↑