diff --git a/www-api/app/Filters/Cors.php b/www-api/app/Filters/Cors.php index be9c55b6..35bdab97 100644 --- a/www-api/app/Filters/Cors.php +++ b/www-api/app/Filters/Cors.php @@ -49,7 +49,7 @@ class Cors implements FilterInterface header("Access-Control-Allow-Methods: GET, PUT, POST, DELETE, PATCH, OPTIONS"); header("Access-Control-Allow-Credentials: true"); header("Access-Control-Max-Age: 3600"); - header('content-type: application/json; charset=utf-8'); + #header('content-type: application/json; charset=utf-8'); $method = $_SERVER['REQUEST_METHOD']; if ($method == "OPTIONS") { header("HTTP/1.1 200 OK CORS"); diff --git a/www-api/nginx/nginx.conf b/www-api/nginx/nginx.conf index 4035aa46..7b62df67 100644 --- a/www-api/nginx/nginx.conf +++ b/www-api/nginx/nginx.conf @@ -35,6 +35,7 @@ http { log_not_found off; } + add_header Access-Control-Allow-Origin *; location / { try_files $uri $uri/ /index.php$is_args$args; } @@ -52,39 +53,6 @@ http { deny all; } - # - # Wide-open CORS config for nginx - # - location / { - if ($request_method = 'OPTIONS') { - add_header 'Access-Control-Allow-Origin' '*'; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; - # - # Custom headers and headers various browsers *should* be OK with but aren't - # - add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; - # - # Tell client that this pre-flight info is valid for 20 days - # - add_header 'Access-Control-Max-Age' 1728000; - add_header 'Content-Type' 'text/plain; charset=utf-8'; - add_header 'Content-Length' 0; - return 204; - } - if ($request_method = 'POST') { - add_header 'Access-Control-Allow-Origin' '*' always; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS' always; - add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range' always; - add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range' always; - } - if ($request_method = 'GET') { - add_header 'Access-Control-Allow-Origin' '*' always; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS' always; - add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range' always; - add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range' always; - } - } - location /svs/bko/ { try_files $uri $uri/ /svs/bko/bkove.php?$args; proxy_intercept_errors off;