Skip to Main Content

Identity & Platform

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

OCI Identity Domain Cloud Gate CORS allowlist

Hi All,

We are planning to remediate a CORS security finding by updating cloudGateCorsSettings in our OCI Identity Domain to restrict cloudGateCorsAllowedOrigins to trusted browser origins.

Before implementing this change, we would like guidance on the following:

  1. What are the recommended best practices for configuring cloudGateCorsAllowedOrigins?
  2. Is there any way to identify browser origins that accessed the Identity Domain over the last 30 or 180 days through logs, reports, audit, or metrics?
  3. Are there any Oracle-managed services, such as OIC, VBCS, SaaS, API Gateway, or related Identity Domain components, whose origins should be included in the allowlist by default?
  4. Are there any internal Identity Domain or Cloud Gate endpoints that must remain accessible after enabling a restricted CORS allowlist?
  5. Is there a recommended validation checklist before rolling this change to production?

Our objective is to implement a minimal and secure allowlist without impacting Oracle-managed services or existing application integrations.

Regards,

Arindam.

Comments
Post Details
Added on Jul 3 2026
0 comments
31 views