# Setup Cross-Origin Resource Sharing (CORS)

**URL:** <https://meta.discourse.org/t/setup-cross-origin-resource-sharing-cors/270819>\
**Category:** Self-Hosting\
**Tags:** how-to\
**Created:** [July 6, 2023, 9:46pm UTC](https://meta.discourse.org/t/setup-cross-origin-resource-sharing-cors/270819 "2023-07-06T21:46:39Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![HaPe](https://avatars.discourse-cdn.com/v4/letter/h/5e9695/32.png) [@HaPe](https://meta.discourse.org/u/HaPe)\
**Post date:** [January 13, 2026, 9:56pm UTC](https://meta.discourse.org/t/setup-cross-origin-resource-sharing-cors/270819/9 "2026-01-13T21:56:29Z")

</div>

Hi! I want to load `/latest.json` from a potentially unsafe website that I do not control. Is it possible to enable CORS headers only for certain URLs like `/latest.json` but not for, e.g., `/u/myname/user-menu-private-messages`?

---

_[View the full topic](https://meta.discourse.org/t/setup-cross-origin-resource-sharing-cors/270819)._
