hide the header Access-Control-Allow-Origin before adding it.
This commit is contained in:
parent
fea452d7b1
commit
634744cd71
|
@ -1,6 +1,7 @@
|
||||||
{% if nginx_cors_extended_rules %}
|
{% if nginx_cors_extended_rules %}
|
||||||
if ($request_method = 'OPTIONS') {
|
if ($request_method = 'OPTIONS') {
|
||||||
{% if nginx_cors_limit_origin %}
|
{% if nginx_cors_limit_origin %}
|
||||||
|
proxy_hide_header Access-Control-Allow-Origin;
|
||||||
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
||||||
{% else %}
|
{% else %}
|
||||||
add_header 'Access-Control-Allow-Origin' '*';
|
add_header 'Access-Control-Allow-Origin' '*';
|
||||||
|
@ -21,6 +22,7 @@ if ($request_method = 'OPTIONS') {
|
||||||
}
|
}
|
||||||
if ($request_method = 'POST') {
|
if ($request_method = 'POST') {
|
||||||
{% if nginx_cors_limit_origin %}
|
{% if nginx_cors_limit_origin %}
|
||||||
|
proxy_hide_header Access-Control-Allow-Origin;
|
||||||
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
||||||
{% else %}
|
{% else %}
|
||||||
add_header 'Access-Control-Allow-Origin' '*';
|
add_header 'Access-Control-Allow-Origin' '*';
|
||||||
|
@ -32,8 +34,10 @@ if ($request_method = 'POST') {
|
||||||
}
|
}
|
||||||
if ($request_method = 'GET') {
|
if ($request_method = 'GET') {
|
||||||
{% if nginx_cors_limit_origin %}
|
{% if nginx_cors_limit_origin %}
|
||||||
|
proxy_hide_header Access-Control-Allow-Origin;
|
||||||
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
||||||
{% else %}
|
{% else %}
|
||||||
|
proxy_hide_header Access-Control-Allow-Origin;
|
||||||
add_header 'Access-Control-Allow-Origin' '*';
|
add_header 'Access-Control-Allow-Origin' '*';
|
||||||
{% endif %}
|
{% endif %}
|
||||||
add_header 'Access-Control-Allow-Credentials' 'true';
|
add_header 'Access-Control-Allow-Credentials' 'true';
|
||||||
|
@ -43,8 +47,10 @@ if ($request_method = 'GET') {
|
||||||
}
|
}
|
||||||
{% else %}
|
{% else %}
|
||||||
{% if nginx_cors_limit_origin %}
|
{% if nginx_cors_limit_origin %}
|
||||||
|
proxy_hide_header Access-Control-Allow-Origin;
|
||||||
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
add_header 'Access-Control-Allow-Origin' '{{ nginx_cors_acl_origin | default("$http_origin") }}';
|
||||||
{% else %}
|
{% else %}
|
||||||
|
proxy_hide_header Access-Control-Allow-Origin;
|
||||||
add_header 'Access-Control-Allow-Origin' '*';
|
add_header 'Access-Control-Allow-Origin' '*';
|
||||||
{% endif %}
|
{% endif %}
|
||||||
if ($request_method = OPTIONS ) {
|
if ($request_method = OPTIONS ) {
|
||||||
|
|
Loading…
Reference in New Issue