2015-07-08 19:27:56 +08:00
|
|
|
module.exports = function cors(extraHeaders) {
|
|
|
|
return function(req, res, next) {
|
|
|
|
var baseHeaders = "X-Requested-With, X-Prototype-Version, X-CSRF-Token";
|
|
|
|
if(extraHeaders) {
|
|
|
|
baseHeaders += ", " + extraHeaders;
|
|
|
|
}
|
2015-09-17 08:03:09 +08:00
|
|
|
res.set("Access-Control-Allow-Origin", "*");
|
|
|
|
res.set("Access-Control-Allow-Headers", baseHeaders);
|
2015-07-08 19:27:56 +08:00
|
|
|
next();
|
|
|
|
};
|
2015-09-17 08:03:09 +08:00
|
|
|
};
|