Optional ReadonlyallowedRequest headers allowed in preflight requests, or null/omitted if none are allowed.
ReadonlyallowedB2 and S3 operations permitted by this rule. At least one operation is required, and every value must be from CORS_ALLOWED_OPERATIONS.
ReadonlyallowedOrigins allowed to make cross-origin requests (e.g., 'https://example.com').
At least one origin is required.
ReadonlycorsUnique name identifying this CORS rule within the bucket.
Must be 6-63 characters, match [A-Za-z0-9-], and not start with b2-.
Optional ReadonlyexposeResponse headers exposed to the browser, or null/omitted if none are exposed.
ReadonlymaxMaximum time (0-86400 seconds) browsers may cache the preflight response.
Cross-Origin Resource Sharing (CORS) rule for browser-based access to a bucket. A bucket may have up to CORS_RULES_MAX_COUNT rules, and each rule's name, allowed origins, allowed operations, allowed headers, and exposed headers must total less than CORS_RULE_MAX_BYTES UTF-8 bytes.