DRYD-2122: Disable CORS for SAML endpoints#543
Open
mikejritter wants to merge 1 commit into
Open
Conversation
This uses a wildcard to disable cors so that IdPs can send different origins to cspace-services backend when performing sso.
spirosdi
approved these changes
Jun 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this do?
This uses a wildcard to disable cors so that IdPs can send different origins to cspace-services backend when performing sso.
Why are we doing this? (with JIRA link)
Jira: https://collectionspace.atlassian.net/browse/DRYD-2122
This is effecting SSO for one of the hosted clients where their IdP is sending an Origin header which is not allowed by the CORS settings of the server. This prevents the SSO login flow from completing.
How should this be tested? Do these changes have associated tests?
SSO Testingwiki page to setup an Auth0 instance (or use my configuration which I've added to the page)service-config-sso.xmlinto thelocalcspace config directory.403response is ok.Dependencies for merging? Releasing to production?
None
Has the application documentation been updated for these changes?
SSO or CORS documentation could potentially be updated.
Did someone actually run this code to verify it works?
@mikejritter tested locally... though against dev.
Have any new security vulnerabilities been handled?
n/a