# Setting Access-Control-Allow-Origin header to requesting client's IP

**URL:** <https://community.wowza.com/t/setting-access-control-allow-origin-header-to-requesting-clients-ip/578>\
**Category:** Wowza Streaming Engine\
**Created:** [June 17, 2016, 11:40am UTC](https://community.wowza.com/t/setting-access-control-allow-origin-header-to-requesting-clients-ip/578 "2016-06-17T11:40:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/system/32/447_2.png) [@system](https://community.wowza.com/u/system)\
**Post date:** [June 17, 2016, 11:40am UTC](https://community.wowza.com/t/setting-access-control-allow-origin-header-to-requesting-clients-ip/578/1 "2016-06-17T11:40:26Z")

</div>

Is it possible to set Access-Control-Allow-Origin to the IP of the client making the request instead of “_" (not hard-coded to a specific IP, but set dynamically depending on the IP of the client)? We’re looking into using a load balancer which utilizes sticky sessions with cookies, and CORS doesn’t allow cookies to be sent in Javascript HTTP requests when Access-Control-Allow-Origin is set to "_”.

Thanks!

---

<div class="post-metadata">

**Author:** ![Rhys\_Causey](https://avatars.discourse-cdn.com/v4/letter/r/73ab20/32.png) [@Rhys\_Causey](https://community.wowza.com/u/Rhys_Causey)\
**Post date:** [June 17, 2016, 1:51pm UTC](https://community.wowza.com/t/setting-access-control-allow-origin-header-to-requesting-clients-ip/578/2 "2016-06-17T13:51:59Z")

</div>

> Is it possible to set Access-Control-Allow-Origin to the IP of the client making the request instead of “_" (not hard-coded to a specific IP, but set dynamically depending on the IP of the client)? We’re looking into using a load balancer which utilizes sticky sessions with cookies, and CORS doesn’t allow cookies to be sent in Javascript HTTP requests when Access-Control-Allow-Origin is set to "_”.
> 
> Thanks!

I think I figured it out. I added this to a custom module:

httpSession.setUserHTTPHeader(“Access-Control-Allow-Origin”, httpSession.getHTTPHeader(“origin”));

And it seems to do what I need. (I actually needed origin, not client IP!)

---

<div class="post-metadata">

**Author:** ![Jason\_Hilton](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/jason_hilton/32/437_2.png) [@Jason\_Hilton](https://community.wowza.com/u/Jason_Hilton)\
**Post date:** [July 4, 2016, 9:33am UTC](https://community.wowza.com/t/setting-access-control-allow-origin-header-to-requesting-clients-ip/578/3 "2016-07-04T09:33:11Z")

</div>

Hi,

That’s great news, thanks for the update.

Regards,

Jason
