Thanks to visit codestin.com
Credit goes to github.com

Skip to content

[help] Access-Control-Allow-Credentials: true, Access-Control-Allow-Origin cannot be *, but I did not find the corresponding implementation #117

@rentiansheng

Description

@rentiansheng

If ajax wants to carry cookies when sending cross-domain requests, the withcredentials attribute of the request object must be set to true.

At this time, the server response header Access-Control-Allow-Origin cannot be * (asterisk), it must be a whitelist style, that is, which URLs must be allowed to access, except for the response header Access-Control-Allow-Origin Setting, you must also set another response header: Access-Control-Allow-Credentials: true.

	if c.allowCredentials {
                 // TODO:Missing settings for Access-Control-Allow-Origin, when AllowedOrigins=*
		headers.Set("Access-Control-Allow-Credentials", "true")
	}

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions