CORS_ALLOWED_ORIGINS = [ "https://example.com", "http://localhost:3000", ] CORS_ALLOW_ALL_ORIGINS = True CORS_ALLOW_CREDENTIALS = True CSRF_TRUSTED_ORIGINS = [ 'https://api.meridynpharma.com/', 'http://api.meridynpharma.com/' 'https://api.meridynpharma.com' ]