Use maps.googleapi.com with "same-origin" cross origin policy

Viewed 228

I'm using the google maps API in a web application which can, to my knowledge, only be loaded with a script tag: <script type="text/javascript" src="https://maps.googleapis.com/maps/api/js?key={your_api_key}&libraries=drawing,geometry"></script>.

Due to a new feature which uses a WebAssembly module which is built with pthread support I will have to adjust the CORS policy for our application / site because SharedArrayBuffer is affected by Meltdown/Spectre:

"Cross-Origin-Embedder-Policy": "require-corp"
"Cross-Origin-Opener-Policy": "same-origin"

This works fine for almost all of the application but since the googleapis CDN does not set the "Access-Control-Allow-Origin" header to "*" it is now being blocked.

Is there a way to enable this somehow or by using another CDN / Endpoint from google?

1 Answers

I've done two things in order to get this working.

  1. Accepted that it's not possible to use SharedArrayBuffer right now and modified the code so it could be build without using pthreads and SharedArrayBuffer
  2. Contacted google support about the CORS policy issue

Some time ago I received an E-Mail from google support stating that they now added proper CORS rules on their end point so it should be working now.

However, I did not test it out because I don't need it anymore but hopefully other devs won't get into trouble with google maps API and CORS anymore.

Related