mirror of
https://github.com/invoiceninja/invoiceninja.git
synced 2025-05-24 02:14:21 -04:00
Fixes for CORS
This commit is contained in:
parent
24b7cb7509
commit
37de17cf38
@ -101,6 +101,7 @@ class Kernel extends HttpKernel
|
||||
'throttle:60,1',
|
||||
'bindings',
|
||||
'query_logging',
|
||||
Cors::class,
|
||||
],
|
||||
'client' => [
|
||||
EncryptCookies::class,
|
||||
@ -111,6 +112,7 @@ class Kernel extends HttpKernel
|
||||
VerifyCsrfToken::class,
|
||||
SubstituteBindings::class,
|
||||
QueryLogging::class,
|
||||
Cors::class,
|
||||
],
|
||||
'shop' => [
|
||||
'throttle:120,1',
|
||||
@ -125,7 +127,7 @@ class Kernel extends HttpKernel
|
||||
ShareErrorsFromSession::class,
|
||||
SubstituteBindings::class,
|
||||
QueryLogging::class,
|
||||
VerifyCsrfToken::class,
|
||||
// VerifyCsrfToken::class,
|
||||
],
|
||||
];
|
||||
|
||||
|
@ -25,6 +25,7 @@ class Cors
|
||||
$response = $next($request);
|
||||
|
||||
$response->headers->set('Access-Control-Allow-Origin', '*');
|
||||
$response->headers->set('Access-Control-Allow-Credentials', 'True');
|
||||
$response->headers->set('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
|
||||
$response->headers->set('Access-Control-Allow-Headers', 'X-API-COMPANY-KEY,X-API-SECRET,X-API-TOKEN,X-API-PASSWORD,DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,X-CSRF-TOKEN,X-LIVEWIRE');
|
||||
$response->headers->set('Access-Control-Expose-Headers', 'X-APP-VERSION,X-MINIMUM-CLIENT-VERSION');
|
||||
|
Loading…
x
Reference in New Issue
Block a user