...
Code Block |
---|
# Always set these headers.Header always set Access-Control-Allow-Origin "*" Header always set Access-Control-Allow-Methods "POST, GET, OPTIONS, DELETE, PUT" Header always set Access-Control-Max-Age "1000" Header always set Access-Control-Allow-Headers "x-requested-with, Content-Type, origin, authorization, accept, client-security-token, pos-session, storelogistic-session" # Added a rewrite to respond with a 200 SUCCESS on every OPTIONS request. RewriteEngine On OnRewriteCondRewriteCond %{REQUEST_METHOD} OPTIONSRewriteRuleOPTIONS RewriteRule ^(.*)$ $1 [R=200,L] |
Với nginx, sửa Nginx config : ở
magento root folder/nginx.conf.sample
Code Block |
---|
# # Wide-open CORS config for nginx # location / { if ($request_method = 'OPTIONS') { add_header 'Access-Control-Allow-Origin' '*'; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, DELETE, PUT' always; # # Custom headers and headers various browsers *should* be OK with but aren't # add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,pos-session,storelogistic-session' always; # # Tell client that this pre-flight info is valid for 20 days # add_header 'Access-Control-Max-Age' 1728000; add_header 'Content-Type' 'text/plain; charset=utf-8'; add_header 'Content-Length' 0; return 204; } add_header 'Access-Control-Allow-Origin' '*' always; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, DELETE, PUT' always; add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,pos-session,storelogistic-session' always; add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range' always; } |
...