Send just * for Access-Control-Allow-Origin header in CORS OPTIONS requests (again closes #681)

This commit is contained in:
Bernd Bestel
2020-04-21 21:05:32 +02:00
parent 7fb76df33a
commit 98f2276e17

View File

@@ -17,11 +17,10 @@ class CorsMiddleware extends BaseMiddleware
$routingResults = $routeContext->getRoutingResults();
$methods = $routingResults->getAllowedMethods();
//$requestHeaders = $request->getHeaderLine('Access-Control-Request-Headers');
$origin = $request->getHeaderLine('Origin');
$response = $handler->handle($request);
$response = $response->withHeader('Access-Control-Allow-Origin', $origin);
$response = $response->withHeader('Access-Control-Allow-Origin', '*');
$response = $response->withHeader('Access-Control-Allow-Methods', implode(',', $methods));
$response = $response->withHeader('Access-Control-Allow-Headers', 'Content-Type,GROCY-API-KEY');