Cross-Origin-Resource-Policy (CORP) header
The HTTPCross-Origin-Resource-Policyresponse header (CORP) indicates that the browser should blockno-cors cross-origin or cross-site requests to the given resource.
It specifies resource owner's policy for what sites/origins should be allowed to load this resource.
| Header type | Response header |
|---|
In this article
Syntax
http
Cross-Origin-Resource-Policy: same-site | same-origin | cross-originDirectives
same-siteResources can only be loaded from the same site.
same-originResources can only be loaded from the same origin.
cross-originResources can be loaded by any other origin/website.
Examples
For more examples, seehttps://resourcepolicy.fyi/.
Disallowing cross-origin no-cors requests
TheCross-Origin-Resource-Policy header below will cause compatible user agents to disallow cross-origin no-cors requests:
http
Cross-Origin-Resource-Policy: same-originSpecifications
| Specification |
|---|
| Fetch> # cross-origin-resource-policy-header> |