DreamFactory CORS API
Cross-Origin Resource Sharing configuration
Cross-Origin Resource Sharing configuration
openapi: 3.1.0
info:
title: DreamFactory System Admin CORS API
description: The DreamFactory System API provides administrative management capabilities for DreamFactory instances. It allows administrators to manage services, apps, roles, users, CORS configurations, email templates, environment settings, lookups, events, scripts, and more. All system resources are accessible under the /api/v2/system/ base path. Authentication requires either an X-DreamFactory-Session-Token header (for system admins) or an X-DreamFactory-API-Key header (for users with appropriate permissions).
version: 2.0.0
contact:
name: DreamFactory Support
url: https://www.dreamfactory.com/support
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0
termsOfService: https://www.dreamfactory.com/terms-of-use
servers:
- url: https://{instance}/api/v2
description: DreamFactory instance
variables:
instance:
default: example.dreamfactory.com
description: Your DreamFactory instance hostname
security:
- sessionToken: []
- apiKey: []
tags:
- name: CORS
description: Cross-Origin Resource Sharing configuration
paths:
/system/cors:
get:
operationId: listCorsConfigs
summary: DreamFactory List CORS configurations
description: Retrieve a list of CORS configurations.
tags:
- CORS
parameters:
- $ref: '#/components/parameters/fields'
- $ref: '#/components/parameters/filter'
- $ref: '#/components/parameters/limit'
- $ref: '#/components/parameters/offset'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/CorsListResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'500':
$ref: '#/components/responses/InternalError'
post:
operationId: createCorsConfig
summary: DreamFactory Create CORS configuration
description: Create a new CORS configuration.
tags:
- CORS
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CorsRequest'
responses:
'201':
description: CORS config created
content:
application/json:
schema:
$ref: '#/components/schemas/CorsResponse'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'500':
$ref: '#/components/responses/InternalError'
/system/cors/{id}:
get:
operationId: getCorsConfig
summary: DreamFactory Get CORS configuration
description: Retrieve a specific CORS configuration by ID.
tags:
- CORS
parameters:
- $ref: '#/components/parameters/id'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/CorsResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalError'
patch:
operationId: updateCorsConfig
summary: DreamFactory Update CORS configuration
description: Update a specific CORS configuration by ID.
tags:
- CORS
parameters:
- $ref: '#/components/parameters/id'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CorsRequest'
responses:
'200':
description: CORS config updated
content:
application/json:
schema:
$ref: '#/components/schemas/CorsResponse'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalError'
delete:
operationId: deleteCorsConfig
summary: DreamFactory Delete CORS configuration
description: Delete a specific CORS configuration by ID.
tags:
- CORS
parameters:
- $ref: '#/components/parameters/id'
responses:
'200':
description: CORS config deleted
content:
application/json:
schema:
$ref: '#/components/schemas/SuccessResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalError'
components:
parameters:
id:
name: id
in: path
required: true
description: Resource identifier.
schema:
type: integer
limit:
name: limit
in: query
description: Maximum number of records to return.
schema:
type: integer
default: 0
filter:
name: filter
in: query
description: SQL-like filter to limit results.
schema:
type: string
fields:
name: fields
in: query
description: Comma-delimited list of fields to return.
schema:
type: string
offset:
name: offset
in: query
description: Number of records to skip for pagination.
schema:
type: integer
default: 0
responses:
NotFound:
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
InternalError:
description: Internal server error
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Unauthorized:
description: Unauthorized - invalid or missing session token or API key
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
BadRequest:
description: Bad request
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
schemas:
CorsResponse:
type: object
properties:
id:
type: integer
path:
type: string
origin:
type: string
header:
type: string
method:
type: integer
max_age:
type: integer
enabled:
type: boolean
created_date:
type: string
format: date-time
last_modified_date:
type: string
format: date-time
CorsRequest:
type: object
properties:
path:
type: string
description: API path to apply CORS to.
origin:
type: string
description: Allowed origin.
header:
type: string
description: Allowed headers.
method:
type: integer
description: Bitmask of allowed HTTP methods.
max_age:
type: integer
description: Max age for preflight caching in seconds.
enabled:
type: boolean
description: Whether CORS config is enabled.
required:
- path
- origin
CorsListResponse:
type: object
properties:
resource:
type: array
items:
$ref: '#/components/schemas/CorsResponse'
ErrorResponse:
type: object
properties:
error:
type: object
properties:
code:
type: integer
description: Error code.
message:
type: string
description: Error message.
context:
type: object
description: Additional error context.
SuccessResponse:
type: object
properties:
success:
type: boolean
securitySchemes:
sessionToken:
type: apiKey
name: X-DreamFactory-Session-Token
in: header
description: Session token obtained after admin login.
apiKey:
type: apiKey
name: X-DreamFactory-API-Key
in: header
description: API key associated with a registered application.
externalDocs:
description: DreamFactory Documentation
url: https://guide.dreamfactory.com/docs/