aravind changes
This commit is contained in:
@@ -72,6 +72,12 @@ func cors(origins []string) func(http.Handler) http.Handler {
|
||||
}
|
||||
|
||||
w.Header().Set("Access-Control-Allow-Origin", origin)
|
||||
// The frontend sends `credentials: "include"`, and a browser
|
||||
// discards any response to such a request that does not carry this
|
||||
// header — preflight included. Safe only because the origin was
|
||||
// matched exactly above and is echoed back one at a time; "*" is
|
||||
// never sent, which is the pairing the spec forbids.
|
||||
w.Header().Set("Access-Control-Allow-Credentials", "true")
|
||||
|
||||
// Authentication is a cookie, so the browser will neither send it
|
||||
// nor expose the response without this. It is set for allowlisted
|
||||
|
||||
Reference in New Issue
Block a user