diff --git a/app/Http/Kernel.php b/app/Http/Kernel.php index 2559cb6bcada..08d05edce1ee 100644 --- a/app/Http/Kernel.php +++ b/app/Http/Kernel.php @@ -101,6 +101,7 @@ class Kernel extends HttpKernel 'throttle:60,1', 'bindings', 'query_logging', + Cors::class, ], 'client' => [ EncryptCookies::class, @@ -111,6 +112,7 @@ class Kernel extends HttpKernel VerifyCsrfToken::class, SubstituteBindings::class, QueryLogging::class, + Cors::class, ], 'shop' => [ 'throttle:120,1', @@ -125,7 +127,7 @@ class Kernel extends HttpKernel ShareErrorsFromSession::class, SubstituteBindings::class, QueryLogging::class, - VerifyCsrfToken::class, + // VerifyCsrfToken::class, ], ]; diff --git a/app/Http/Middleware/Cors.php b/app/Http/Middleware/Cors.php index 1291e5ba912e..66de2d22b936 100644 --- a/app/Http/Middleware/Cors.php +++ b/app/Http/Middleware/Cors.php @@ -25,6 +25,7 @@ class Cors $response = $next($request); $response->headers->set('Access-Control-Allow-Origin', '*'); + $response->headers->set('Access-Control-Allow-Credentials', 'True'); $response->headers->set('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS'); $response->headers->set('Access-Control-Allow-Headers', 'X-API-COMPANY-KEY,X-API-SECRET,X-API-TOKEN,X-API-PASSWORD,DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,X-CSRF-TOKEN,X-LIVEWIRE'); $response->headers->set('Access-Control-Expose-Headers', 'X-APP-VERSION,X-MINIMUM-CLIENT-VERSION');