mirror of
https://github.com/grocy/grocy.git
synced 2025-08-20 04:12:59 +00:00
Send just * for Access-Control-Allow-Origin header in CORS OPTIONS requests (again closes #681)
This commit is contained in:
@@ -17,11 +17,10 @@ class CorsMiddleware extends BaseMiddleware
|
|||||||
$routingResults = $routeContext->getRoutingResults();
|
$routingResults = $routeContext->getRoutingResults();
|
||||||
$methods = $routingResults->getAllowedMethods();
|
$methods = $routingResults->getAllowedMethods();
|
||||||
//$requestHeaders = $request->getHeaderLine('Access-Control-Request-Headers');
|
//$requestHeaders = $request->getHeaderLine('Access-Control-Request-Headers');
|
||||||
$origin = $request->getHeaderLine('Origin');
|
|
||||||
|
|
||||||
$response = $handler->handle($request);
|
$response = $handler->handle($request);
|
||||||
|
|
||||||
$response = $response->withHeader('Access-Control-Allow-Origin', $origin);
|
$response = $response->withHeader('Access-Control-Allow-Origin', '*');
|
||||||
$response = $response->withHeader('Access-Control-Allow-Methods', implode(',', $methods));
|
$response = $response->withHeader('Access-Control-Allow-Methods', implode(',', $methods));
|
||||||
$response = $response->withHeader('Access-Control-Allow-Headers', 'Content-Type,GROCY-API-KEY');
|
$response = $response->withHeader('Access-Control-Allow-Headers', 'Content-Type,GROCY-API-KEY');
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user