Allow API consumer to send credentials on cross-origin requests
This commit is contained in:
parent
196ea16a94
commit
499b06c9e5
@ -3,6 +3,7 @@ class Api::ApplicationController < ApplicationController
|
|||||||
|
|
||||||
def cor_filter
|
def cor_filter
|
||||||
headers['Access-Control-Allow-Origin'] = request.headers['Origin']
|
headers['Access-Control-Allow-Origin'] = request.headers['Origin']
|
||||||
|
headers['Access-Control-Allow-Credentials'] = 'true'
|
||||||
end
|
end
|
||||||
|
|
||||||
def cor_preflight
|
def cor_preflight
|
||||||
|
@ -24,6 +24,7 @@ feature 'API cross origin request' do
|
|||||||
)
|
)
|
||||||
|
|
||||||
response.headers['Access-Control-Allow-Origin'].should == origin
|
response.headers['Access-Control-Allow-Origin'].should == origin
|
||||||
|
response.headers['Access-Control-Allow-Credentials'].should == 'true'
|
||||||
response.headers['Access-Control-Allow-Methods'].should ==
|
response.headers['Access-Control-Allow-Methods'].should ==
|
||||||
'GET, POST, PUT, DELETE'
|
'GET, POST, PUT, DELETE'
|
||||||
response.headers['Access-Control-Allow-Headers'].should ==
|
response.headers['Access-Control-Allow-Headers'].should ==
|
||||||
@ -37,5 +38,6 @@ feature 'API cross origin request' do
|
|||||||
}
|
}
|
||||||
|
|
||||||
response.headers['Access-Control-Allow-Origin'].should == origin
|
response.headers['Access-Control-Allow-Origin'].should == origin
|
||||||
|
response.headers['Access-Control-Allow-Credentials'].should == 'true'
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
Loading…
x
Reference in New Issue
Block a user