Closed drewstewart closed 9 years ago
Been done for ages.
where and how was this implemented? getsandbox.com sure doesn't add a allow header to the output.,,
Hi Klaus,
Can you provide an example please? We replay "Origin" and "Access-Control-Request-Headers" from requests on responses.
Where is the documentation around this behaviour?
Other than being a standard pattern, its not documented i don't think. Will put it on the doco backlog.
CORS headers should be added to responses by default otherwise browsers sure have a hard time making requests.