adding Authorization to Access-Control-Allow-Headers
This commit is contained in:
parent
68b2b1970a
commit
60702faa57
@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
module.exports = function cors(extraHeaders) {
|
module.exports = function cors(extraHeaders) {
|
||||||
return function(req, res, next) {
|
return function(req, res, next) {
|
||||||
var baseHeaders = 'X-Requested-With, X-Prototype-Version, X-CSRF-Token';
|
var baseHeaders = 'X-Requested-With, X-Prototype-Version, X-CSRF-Token, Authorization';
|
||||||
|
|
||||||
if(extraHeaders) {
|
if(extraHeaders) {
|
||||||
baseHeaders += ', ' + extraHeaders;
|
baseHeaders += ', ' + extraHeaders;
|
||||||
|
@ -60,7 +60,8 @@ describe('app-configuration', function() {
|
|||||||
method: 'GET'
|
method: 'GET'
|
||||||
}, RESPONSE_OK, function(err, res) {
|
}, RESPONSE_OK, function(err, res) {
|
||||||
assert.equal(
|
assert.equal(
|
||||||
res.headers['access-control-allow-headers'], 'X-Requested-With, X-Prototype-Version, X-CSRF-Token'
|
res.headers['access-control-allow-headers'],
|
||||||
|
'X-Requested-With, X-Prototype-Version, X-CSRF-Token, Authorization'
|
||||||
);
|
);
|
||||||
assert.equal(res.headers['access-control-allow-origin'], '*');
|
assert.equal(res.headers['access-control-allow-origin'], '*');
|
||||||
done();
|
done();
|
||||||
@ -76,7 +77,8 @@ describe('app-configuration', function() {
|
|||||||
}, RESPONSE_OK, function(err, res) {
|
}, RESPONSE_OK, function(err, res) {
|
||||||
assert.equal(res.body, '');
|
assert.equal(res.body, '');
|
||||||
assert.equal(
|
assert.equal(
|
||||||
res.headers['access-control-allow-headers'], 'X-Requested-With, X-Prototype-Version, X-CSRF-Token'
|
res.headers['access-control-allow-headers'],
|
||||||
|
'X-Requested-With, X-Prototype-Version, X-CSRF-Token, Authorization'
|
||||||
);
|
);
|
||||||
assert.equal(res.headers['access-control-allow-origin'], '*');
|
assert.equal(res.headers['access-control-allow-origin'], '*');
|
||||||
done();
|
done();
|
||||||
@ -158,7 +160,7 @@ describe('app-configuration', function() {
|
|||||||
assert.equal(res.headers['access-control-allow-origin'], '*');
|
assert.equal(res.headers['access-control-allow-origin'], '*');
|
||||||
assert.equal(
|
assert.equal(
|
||||||
res.headers['access-control-allow-headers'],
|
res.headers['access-control-allow-headers'],
|
||||||
"X-Requested-With, X-Prototype-Version, X-CSRF-Token"
|
"X-Requested-With, X-Prototype-Version, X-CSRF-Token, Authorization"
|
||||||
);
|
);
|
||||||
done();
|
done();
|
||||||
});
|
});
|
||||||
|
Loading…
Reference in New Issue
Block a user