More restrictive client access policy
<?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="http://sometrusteddomain.com/>" </allow-from> <grant-to> <resource path="/" include-subpaths="true"/> </grant-to> </policy> <policy> <allow-from> <domain uri="*/>" </allow-from> <grant-to> <resource path="/api"/> </grant-to> </policy> </cross-domain-access> </access-policy>