allow cors - access-control-allow-origin
Overview
bypass cors (access-control-allow-origin) errors, strip csp and x-frame-options security headers, and redirect api requests.
allow cors - access-control-allow-origin is a flat, lightweight developer utility to bypass cors, strip security headers, and configure custom redirects during local api testing. it runs 100% locally in your browser using native manifest v3 declarative rules, requiring zero idle cpu overhead and providing full compatibility with modern security standards. key features: * cors bypass: dynamically modifies response headers to permit cross-origin api queries. * credentials unblock: resolves browser wildcard blocks by matching the active tab's origin and injecting access-control-allow-credentials: true. * auto-disable alarm: automatically switches off the extension after 1, 10, 30, or 60 minutes using native background chrome alarms to prevent security leaks. * redirect mapping: redirects remote api patterns or javascript files (e.g. *zoologyfibre*/*.js*) to local mock routes (e.g. http://localhost:3000/mock.js). * headers stripping: removes content-security-policy (csp, x-webkit-csp, x-content-security-policy) and x-frame-options (frame-options) headers to test frames and embedded resources. * rules mode: choose between blocklist (allow all except exclusions) and allowlist (allow only custom domains) modes. * request counter: tracks intercepted and modified calls in real-time. all overrides run locally. no data is tracked or collected.
0 out of 5No ratings
Details
- Version1.0
- UpdatedJuly 8, 2026
- Offered byananaydubey
- Size15.71KiB
- LanguagesEnglish
- DeveloperAnanay Dubey
Shivalik Hostel Punjab Engineering College, Sector 12 Chandigarh, Chandigarh 160012 INEmail
dubeyananay@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site