Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions docs/user-guide/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -329,6 +329,9 @@ These settings configure the CORS behavior when `PROXY_OPTIONS` is `false` (the
- **Required:** No, defaults to `^(/collections/([^/]+)/items(/[^/]+)?$|/search$)`
- **Example:** `^(/collections/([^/]+)/items(/[^/]+)?$|/search$|/custom$)`

> [!WARNING]
> Requests to paths matched by neither `ITEMS_FILTER_PATH` nor `COLLECTIONS_FILTER_PATH` are proxied **unfiltered**. If your upstream exposes other endpoints that reveal records or statistics about them, such as aggregation (`/aggregate`, `/collections/{id}/aggregate`), collection search (e.g. `/collections-search`), or queryables (`/queryables`, `/collections/{id}/queryables`), extend these patterns to cover them or block those endpoints.

### `COLLECTIONS_FILTER_CLS`

: CQL2 expression factor for collection-level filtering
Expand Down
Loading