Hi All,
We are planning to remediate a CORS security finding by updating cloudGateCorsSettings in our OCI Identity Domain to restrict cloudGateCorsAllowedOrigins to trusted browser origins.
Before implementing this change, we would like guidance on the following:
- What are the recommended best practices for configuring
cloudGateCorsAllowedOrigins?
- Is there any way to identify browser origins that accessed the Identity Domain over the last 30 or 180 days through logs, reports, audit, or metrics?
- Are there any Oracle-managed services, such as OIC, VBCS, SaaS, API Gateway, or related Identity Domain components, whose origins should be included in the allowlist by default?
- Are there any internal Identity Domain or Cloud Gate endpoints that must remain accessible after enabling a restricted CORS allowlist?
- Is there a recommended validation checklist before rolling this change to production?
Our objective is to implement a minimal and secure allowlist without impacting Oracle-managed services or existing application integrations.
Regards,
Arindam.