Class CrossOriginEmbedderPolicyConfig

java.lang.Object
io.camunda.security.configuration.headers.CrossOriginEmbedderPolicyConfig

public class CrossOriginEmbedderPolicyConfig extends Object
Configures Cross-Origin-Embedder-Policy (COEP) header for cross-origin isolation.

COEP controls whether the document can load cross-origin resources that don't explicitly grant permission. When set to 'require-corp' (default), it requires all cross-origin resources to either: - Include a Cross-Origin-Resource-Policy (CORP) header allowing the load - Be requested using CORS

This header works in conjunction with Cross-Origin-Opener-Policy (COOP).

Default: UNSAFE_NONE - Allows the document to load cross-origin resources without giving explicit permission through the CORS protocol or the Cross-Origin-Resource-Policy header.

See Also: