nelmio_cors: defaults: origin_regex: true allow_origin: ['%env(CORS_ALLOW_ORIGIN)%'] allow_methods: ['GET', 'OPTIONS', 'POST', 'PUT', 'PATCH', 'DELETE'] allow_headers: ['Content-Type', 'Authorization'] expose_headers: ['Link'] max_age: 3600 paths: '^/token$': origin_regex: true allow_origin: ['*'] allow_headers: ['Content-Type', 'Authorization'] allow_methods: ['POST', 'OPTIONS'] allow_credentials: true max_age: 3600 '^/authorize$': origin_regex: true allow_origin: ['*'] allow_headers: ['Content-Type', 'Authorization'] allow_methods: ['GET', 'POST', 'OPTIONS'] allow_credentials: true max_age: 3600 '^/login$': origin_regex: true allow_origin: ['*'] allow_headers: ['Content-Type', 'Authorization'] allow_methods: ['GET', 'POST', 'OPTIONS'] allow_credentials: true max_age: 3600