openapi: 3.1.0 info: title: DreamFactory System Admin CORS API description: The DreamFactory System API provides administrative management capabilities for DreamFactory instances. It allows administrators to manage services, apps, roles, users, CORS configurations, email templates, environment settings, lookups, events, scripts, and more. All system resources are accessible under the /api/v2/system/ base path. Authentication requires either an X-DreamFactory-Session-Token header (for system admins) or an X-DreamFactory-API-Key header (for users with appropriate permissions). version: 2.0.0 contact: name: DreamFactory Support url: https://www.dreamfactory.com/support license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 termsOfService: https://www.dreamfactory.com/terms-of-use servers: - url: https://{instance}/api/v2 description: DreamFactory instance variables: instance: default: example.dreamfactory.com description: Your DreamFactory instance hostname security: - sessionToken: [] - apiKey: [] tags: - name: CORS description: Cross-Origin Resource Sharing configuration paths: /system/cors: get: operationId: listCorsConfigs summary: DreamFactory List CORS configurations description: Retrieve a list of CORS configurations. tags: - CORS parameters: - $ref: '#/components/parameters/fields' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/offset' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/CorsListResponse' '401': $ref: '#/components/responses/Unauthorized' '500': $ref: '#/components/responses/InternalError' post: operationId: createCorsConfig summary: DreamFactory Create CORS configuration description: Create a new CORS configuration. tags: - CORS requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CorsRequest' responses: '201': description: CORS config created content: application/json: schema: $ref: '#/components/schemas/CorsResponse' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '500': $ref: '#/components/responses/InternalError' /system/cors/{id}: get: operationId: getCorsConfig summary: DreamFactory Get CORS configuration description: Retrieve a specific CORS configuration by ID. tags: - CORS parameters: - $ref: '#/components/parameters/id' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/CorsResponse' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' patch: operationId: updateCorsConfig summary: DreamFactory Update CORS configuration description: Update a specific CORS configuration by ID. tags: - CORS parameters: - $ref: '#/components/parameters/id' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CorsRequest' responses: '200': description: CORS config updated content: application/json: schema: $ref: '#/components/schemas/CorsResponse' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' delete: operationId: deleteCorsConfig summary: DreamFactory Delete CORS configuration description: Delete a specific CORS configuration by ID. tags: - CORS parameters: - $ref: '#/components/parameters/id' responses: '200': description: CORS config deleted content: application/json: schema: $ref: '#/components/schemas/SuccessResponse' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' components: parameters: id: name: id in: path required: true description: Resource identifier. schema: type: integer limit: name: limit in: query description: Maximum number of records to return. schema: type: integer default: 0 filter: name: filter in: query description: SQL-like filter to limit results. schema: type: string fields: name: fields in: query description: Comma-delimited list of fields to return. schema: type: string offset: name: offset in: query description: Number of records to skip for pagination. schema: type: integer default: 0 responses: NotFound: description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' InternalError: description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Unauthorized: description: Unauthorized - invalid or missing session token or API key content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' BadRequest: description: Bad request content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' schemas: CorsResponse: type: object properties: id: type: integer path: type: string origin: type: string header: type: string method: type: integer max_age: type: integer enabled: type: boolean created_date: type: string format: date-time last_modified_date: type: string format: date-time CorsRequest: type: object properties: path: type: string description: API path to apply CORS to. origin: type: string description: Allowed origin. header: type: string description: Allowed headers. method: type: integer description: Bitmask of allowed HTTP methods. max_age: type: integer description: Max age for preflight caching in seconds. enabled: type: boolean description: Whether CORS config is enabled. required: - path - origin CorsListResponse: type: object properties: resource: type: array items: $ref: '#/components/schemas/CorsResponse' ErrorResponse: type: object properties: error: type: object properties: code: type: integer description: Error code. message: type: string description: Error message. context: type: object description: Additional error context. SuccessResponse: type: object properties: success: type: boolean securitySchemes: sessionToken: type: apiKey name: X-DreamFactory-Session-Token in: header description: Session token obtained after admin login. apiKey: type: apiKey name: X-DreamFactory-API-Key in: header description: API key associated with a registered application. externalDocs: description: DreamFactory Documentation url: https://guide.dreamfactory.com/docs/