From 4a8110414d7d6768c73cc249b95b9ec2c58667a9 Mon Sep 17 00:00:00 2001 From: Filip Skokan Date: Wed, 20 Feb 2019 17:06:16 +0100 Subject: [PATCH] fix: expose only supported cors methods --- lib/helpers/initialize_app.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/helpers/initialize_app.js b/lib/helpers/initialize_app.js index 8ae6d198f..df5919b0e 100644 --- a/lib/helpers/initialize_app.js +++ b/lib/helpers/initialize_app.js @@ -95,7 +95,7 @@ module.exports = function initializeApp() { }; const { routes } = configuration; - const onlyGetCors = getCors({ allowedMethods: 'GET' }); + const onlyGetCors = getCors({ allowMethods: 'GET' }); Object.entries(grants).forEach(([grantType, { handler, parameters }]) => { const { grantTypeHandlers } = instance(this); @@ -142,7 +142,7 @@ module.exports = function initializeApp() { const userinfo = getUserinfo(this); const userInfoCors = getCors({ - allowedMethods: 'GET,POST', exposeHeaders: 'WWW-Authenticate', allowHeaders: 'Authorization', + allowMethods: 'GET,POST', exposeHeaders: 'WWW-Authenticate', allowHeaders: 'Authorization', }); get('userinfo', routes.userinfo, userInfoCors, error(this, 'userinfo.error'), ...userinfo); post('userinfo', routes.userinfo, userInfoCors, error(this, 'userinfo.error'), ...userinfo);