# What is the purpose of Settings -\> Security -\> CORS origins vs similar environment setting?

**URL:** <https://meta.discourse.org/t/what-is-the-purpose-of-settings-security-cors-origins-vs-similar-environment-setting/35331>\
**Category:** Support\
**Created:** [11월 7, 2015, 12:58오후 UTC](https://meta.discourse.org/t/what-is-the-purpose-of-settings-security-cors-origins-vs-similar-environment-setting/35331 "2015-11-07T12:58:36Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)\
**Post date:** [11월 9, 2015, 3:48오후 UTC](https://meta.discourse.org/t/what-is-the-purpose-of-settings-security-cors-origins-vs-similar-environment-setting/35331/3 "2015-11-09T15:48:38Z")

</div>

In a multisite setup, like our hosting, each site can have its own allowed origins by using the “cors origins” setting. Setting DISCOURSE\_CORS\_ORIGIN in app.yml will be global to all sites, which probably isn’t what you want in multisite. If you only have one site in a container, then using DISCOURSE\_CORS\_ORIGIN and “cors origins” will be the same.

---

_[View the full topic](https://meta.discourse.org/t/what-is-the-purpose-of-settings-security-cors-origins-vs-similar-environment-setting/35331)._
