GSA / smartpay-training

Prototype for new GSA SmartPay training quizzes
8 stars 4 forks source link

Misconfigured Access-Control-Allow- Origin Header #577

Open JennaySDavis opened 3 weeks ago

JennaySDavis commented 3 weeks ago

Invicti Enterprise detected a possibly misconfigured Access-Control-Allow-Origin header in the resource's HTTP response. Cross-origin resource sharing (CORS) is a mechanism that allows resources on a web page to be requested outside the domain through XMLHttpRequest. Unless this HTTP header is present, such "cross-domain" requests are forbidden by web browsers, per the same-origin security policy.

Remedy: If this page is intended to be accessible to everyone, you don't need to take any action. Otherwise please follow the guidelines for different architectures below to set this header and permit outside domain.