# How to allow CORS?

**URL:** <https://forum.opensearch.org/t/how-to-allow-cors/13965>\
**Category:** Security\
**Created:** [April 17, 2023, 3:15pm UTC](https://forum.opensearch.org/t/how-to-allow-cors/13965 "2023-04-17T15:15:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![konst3](https://avatars.discourse-cdn.com/v4/letter/k/cdc98d/32.png) [@konst3](https://forum.opensearch.org/u/konst3)\
**Post date:** [April 17, 2023, 3:15pm UTC](https://forum.opensearch.org/t/how-to-allow-cors/13965/1 "2023-04-17T15:15:42Z")

</div>

I am deployng openserach cluster using docker compose

I set enviroment variable

and opensearch.yaml  
http.cors.allow-origin: “\*”

But id doesn’t seem to work

curl -H “User-Agent: Mozilla” -H “Origin: [http://example.com](http://example.com)” -i localhost:9200

HTTP/1.1 403 Forbidden  
content-length: 0

How do I disable it?

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [April 17, 2023, 4:45pm UTC](https://forum.opensearch.org/t/how-to-allow-cors/13965/2 "2023-04-17T16:45:24Z")

</div>

@konst3 Did you disable the security plugin?
