The Mozilla Developer Network describes the Cross-Origin-Resource-Policy (CORP) header like this:

The HTTP Cross-Origin-Resource-Policy response header indicates that the browser should block no-cors cross-origin or cross-site requests to the given resource.


A CORP header can be added in one of two ways, either using the default middleware options:


The above adds the CORP header with a same-origin value.

Or by creating an instance of the SecureHeadersMiddlewareBuilder class using the following code:

var customConfig = SecureHeadersMiddlewareBuilder


The above adds the CORP header with a same-origin value.

Full Options

The CORP header object (known internally as CrossOriginResourcePolicy) has the following options:

  • enum: CrossOriginResourceOptions

The values available for the CrossOriginResourceOptions enum are:

  • CrossOrigin
  • SameSite
  • SameOrigin