we are in process of migration of project from AMS to cloud in AEM.
while security review , we are getting access-control-allow-origin: * , while accessing the content/dam images, which is a high security issue.
we are not setting this in our dispatcher, but we are still getting this.
Do we have any solution for this.
Guessing is it coming from the internal Fastly's CDN?
조회 수
답글
좋아요 수
Are you using connected assets ? If yes then take a look
No we are not using connected assets.
These are simple assets in publish which we are trying to access via publish domain in cloud and getting access-control-allow-origin: *
Can you share the log snippet from console as well as error log from publisher.
Any solutions for this, to control allowed origins?
조회 수
답글
좋아요 수
Do you have any custom servlet where you are defining the header ?
Thanks
조회 수
답글
좋아요 수
No Servlet changes, its coming automatically on Assets/images.
조회 수
답글
좋아요 수
Check /clientheader config in aem dispatcher .
Thanks
조회 수
답글
좋아요 수
조회 수
Like
답글
조회 수
Likes
답글
조회 수
Likes
답글
조회 수
Likes
답글