Multiple domains in aws:access-control-allow-origin JWT token config

0

Hi,

Is it possible to define more than one domain in the "aws:access-control-allow-origin" JWT token config?
I've already tried using a space/comma separated list and a JSON array.

Thanks

已提问 3 年前560 查看次数
1 回答
0

Hello,

The access-contrtol-allow-origin header itself only allows a single domain as the origin or * as a wildcard to allow anything, so multiple origins are not allowed in the JWT token.

A common use case with playback authorization is to have the IVS Player embedded in a website so the access-control-allow-origin can be set to the domain of that site, and therefore only allowing playback sessions to originate from the one domain.

In a case where multiple origins are required, an example implementation would be to have logic in an application that can determine the origin of a request, verify that it's in a list of approved origins, then set that origin in the JWT payload before signing and returning the playback URL + access token.

Please let us know if we can provide additional information.

已回答 3 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则