Skip to content

Commit 0755a29

Browse files
committed
fix Access-Control-Allow-Headers to match exact
1 parent 2a200fc commit 0755a29

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/middlewares.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -132,7 +132,7 @@ function handleParseHeaders(req, res, next) {
132132
var allowCrossDomain = function(req, res, next) {
133133
res.header('Access-Control-Allow-Origin', '*');
134134
res.header('Access-Control-Allow-Methods', 'GET,PUT,POST,DELETE,OPTIONS');
135-
res.header('Access-Control-Allow-Headers', '*');
135+
res.header('Access-Control-Allow-Headers', 'X-Parse-REST-API-Key, X-Parse-Javascript-Key, X-Parse-Application-Id, X-Parse-Client-Version, X-Parse-Session-Token, X-Requested-With, X-Parse-Revocable-Session, Content-Type');
136136

137137
// intercept OPTIONS method
138138
if ('OPTIONS' == req.method) {

0 commit comments

Comments
 (0)