diff --git a/roles/bodhi2/base/templates/staging.ini.j2 b/roles/bodhi2/base/templates/staging.ini.j2 index 408e888c40..9cec2669ea 100644 --- a/roles/bodhi2/base/templates/staging.ini.j2 +++ b/roles/bodhi2/base/templates/staging.ini.j2 @@ -355,6 +355,14 @@ openid.provider = https://id.stg.fedoraproject.org/openid/ openid.url = https://id.stg.fedoraproject.org/ openid_template = {username}.id.fedoraproject.org +# CORS allowed origins for cornice services +# This can be wide-open. read-only, we don't care as much about. +cors_origins_ro = * +# This should be more locked down to avoid cross-site request forgery. +cors_origins_rw = bodhi.stg.fedoraproject.org +cors_connect_src = https://*.fedoraproject.org/ wss://hub.fedoraproject.org:9939/ + + ## ## Pyramid settings ##