{ "$schema": "https://json-schema.org/draft/2020-12/schema", "title": "CorsRule", "type": "object", "description": "CORS rule for the Blob service.", "properties": { "AllowedOrigins": { "type": "string", "description": "Comma-separated list of origin domains that are allowed via CORS." }, "AllowedMethods": { "type": "string", "description": "Comma-separated list of HTTP methods that are allowed. Options are DELETE, GET, HEAD, MERGE, POST, OPTIONS, PUT." }, "AllowedHeaders": { "type": "string", "description": "Comma-separated list of headers allowed to be part of the cross-origin request." }, "ExposedHeaders": { "type": "string", "description": "Comma-separated list of response headers to expose to CORS clients." }, "MaxAgeInSeconds": { "type": "integer", "description": "The maximum amount of time in seconds that a browser should cache the preflight OPTIONS request." } } }