Allow cross-domain calls
cross-domain policy to make the API accessible from Adobe Flash and Microsoft Silverlight browser-based clients.
Set the policy's elements and child elements in the order provided in the policy statement. Learn more about how to set or edit API Management policies.
<cross-domain> <!-Policy configuration is in the Adobe cross-domain policy file format, see https://www.adobe.com/devnet-docs/acrobatetk/tools/AppSec/CrossDomain_PolicyFile_Specification.pdf--> </cross-domain>
* wildcard with care in policy settings. This configuration may be overly permissive and may make an API more vulnerable to certain API security threats.
Child elements must conform to the Adobe cross-domain policy file specification.
<cross-domain> <cross-domain-policy> <allow-http-request-headers-from domain='*' headers='*' /> </cross-domain-policy> </cross-domain>
For more information about working with policies, see: