comparison mod_http_upload/mod_http_upload.lua @ 3380:765735bb590b

mod_http_upload: Disallow POST in CORS
author Emmanuel Gil Peyrot <linkmauve@linkmauve.fr>
date Sun, 18 Nov 2018 18:38:37 +0100
parents f1c1f6bc4892
children a5a50cd34386
comparison
equal deleted inserted replaced
3379:f1c1f6bc4892 3380:765735bb590b
230 end 230 end
231 231
232 -- http service 232 -- http service
233 local function set_cross_domain_headers(response) 233 local function set_cross_domain_headers(response)
234 local headers = response.headers; 234 local headers = response.headers;
235 headers.access_control_allow_methods = "GET, PUT, POST, OPTIONS"; 235 headers.access_control_allow_methods = "GET, PUT, OPTIONS";
236 headers.access_control_allow_headers = "Content-Type"; 236 headers.access_control_allow_headers = "Content-Type";
237 headers.access_control_max_age = "7200"; 237 headers.access_control_max_age = "7200";
238 headers.access_control_allow_origin = response.request.headers.origin or "*"; 238 headers.access_control_allow_origin = response.request.headers.origin or "*";
239 return response; 239 return response;
240 end 240 end