Skip to content

Lambda  >  Structures  >  Cors

Cors

Structure Class

Cors dataclass

The cross-origin resource sharing (CORS) settings for your Lambda function URL. Use CORS to grant access to your function URL from any origin. You can also use CORS to control access for specific HTTP headers and methods in requests to your function URL.

Attributes

allow_credentials class-attribute instance-attribute
allow_credentials: bool | None = None

Whether to allow cookies or other credentials in requests to your function URL. The default is false.

allow_headers class-attribute instance-attribute
allow_headers: list[str] | None = None

The HTTP headers that origins can include in requests to your function URL. For example: Date, Keep-Alive, X-Custom-Header.

allow_methods class-attribute instance-attribute
allow_methods: list[str] | None = None

The HTTP methods that are allowed when calling your function URL. For example: GET, POST, DELETE, or the wildcard character (*).

allow_origins class-attribute instance-attribute
allow_origins: list[str] | None = None

The origins that can access your function URL. You can list any number of specific origins, separated by a comma. For example: https://www.example.com, http://localhost:60905.

Alternatively, you can grant access to all origins using the wildcard character (*).

expose_headers class-attribute instance-attribute
expose_headers: list[str] | None = None

The HTTP headers in your function response that you want to expose to origins that call your function URL. For example: Date, Keep-Alive, X-Custom-Header.

max_age class-attribute instance-attribute
max_age: int | None = None

The maximum amount of time, in seconds, that web browsers can cache results of a preflight request. By default, this is set to 0, which means that the browser doesn't cache results.