- Newest
- Most votes
- Most comments
Hello,
The access-contrtol-allow-origin header itself only allows a single domain as the origin or * as a wildcard to allow anything, so multiple origins are not allowed in the JWT token.
A common use case with playback authorization is to have the IVS Player embedded in a website so the access-control-allow-origin can be set to the domain of that site, and therefore only allowing playback sessions to originate from the one domain.
In a case where multiple origins are required, an example implementation would be to have logic in an application that can determine the origin of a request, verify that it's in a list of approved origins, then set that origin in the JWT payload before signing and returning the playback URL + access token.
Please let us know if we can provide additional information.
Relevant content
- asked a year ago
- asked a year ago
- AWS OFFICIALUpdated 8 months ago
- AWS OFFICIALUpdated a month ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated a year ago