// the find
adamchainz/django-cors-headers
Django app for handling the server headers required for Cross-Origin Resource Sharing (CORS)
The standard middleware for adding CORS headers to a Django app, maintained by Adam Johnson since 2016 after the original went unmaintained. It's the default choice anyone reaches for when a Django API needs to serve cross-origin requests, whether that's a decoupled frontend or third-party consumers.
Configuration is explicit and layered correctly — allowed origins, regex origins, or allow-all, plus a CORS_URLS_REGEX to scope it to just /api/ instead of the whole site. The check_request_enabled signal is a real escape hatch for dynamic origin lists (e.g. multi-tenant setups reading allowed hosts from a model) rather than forcing static settings. 100% test coverage claim backed by a CI badge, and it's explicit about the CSRF_TRUSTED_ORIGINS interaction, which is the thing people usually get wrong and file confused issues about.
It's middleware-only — there's no support for anything outside the request/response header cycle, so if you're on ASGI with websockets or need per-view overrides beyond the regex, you're patching around it. CORS_ALLOW_ALL_ORIGINS combined with CORS_ALLOW_CREDENTIALS is a footgun that's easy to misconfigure into an open CORS policy with cookies attached, and the README documents the danger but the library doesn't stop you. Single maintainer bus factor despite 40+ contributors historically — most of the churn now looks like Adam Johnson alone based on the release cadence implied by the changelog structure.