CORSNonWildcardRequestHeadersSupport

CORS non-wildcard request headers support

Supported on:

  • Chrome (Windows) since version 97

Description:

Configures support of CORS non-wildcard request headers.

Samsung Browser version 97 introduces support for CORS non-wildcard request headers. When scripts make a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. "Explicitly" here means that the wild card symbol "*" doesn't cover the Authorization header.

If this policy is not set, or set to True, Samsung Browser will support the CORS non-wildcard request headers and behave as described above.

When this policy is set to False, Samsung Browser will allow the wildcard symbol ("*") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.

This Enterprise policy is temporary; it's intended to be removed in the future.

true = Support CORS non-wildcard request headers.
false = Do not support CORS non-wildcard request headers.

Supported features:

  • Applied to browser without restart. Note that some ongoing tasks may not be affected.
  • Applied at Samsung Browser profile level.

Data type:

Boolean
Windows:REG_DWORD

Windows registry location:

Software\Policies\Samsung\Internet\CORSNonWildcardRequestHeadersSupport

Example value:

0x00000001

More policies under Miscellaneous: