Comments (4)
Just received another bug report about this (copy-pasta'd below). Will get this fixed in the next couple of days.
Hey, I just thought I would drop you a note. I might have a minor bug fix, but I'm not sure if it strictly relates to CORS. Chrome has been giving me errors for a while - refusing to get unsafe headers. I believe the solution is: Access-Control-Expose-Headers. To make Chrome happy, I did the following:
Config:
var corsOptions = {
exposeHeaders : 'Content-Range, X-Content-Range'
};
app.use(cors(corsOptions));
New Method
function configureExposeHeaders(options, req) {
var headers = options.exposeHeaders;
if (!headers) {
return null;
} else if (headers.join) {
// .headers is an array, so turn it into a string
headers = headers.join(',');
}
if (headers && headers.length) {
return {
key : 'Access-Control-Expose-Headers',
value : headers
};
}
return null;
}
Added it into the (req.method === 'OPTIONS')
's ELSE block.
(i.e. it fires every other time)
headers.push(configureExposeHeaders(options, req));
from cors.
Fixed and pushed to npm as version 2.2.0.
Set the exposedHeaders
property of the options passed into the cors middleware to use.
from cors.
Hi @ix-xerri you're right, that isn't currently supported. I haven't seen this header before, but I'll take a look at implementing it soon.
http://www.w3.org/TR/cors/#access-control-expose-headers-response-header
from cors.
Express examples usually show CSRF tokens inside some jade template. I include it in the response header and have the client store it in memory so that the next request would contain the CSRF token. To be able to access the header of a CORS response via javascript you need Access-Control-Expose-Headers
Thanks
from cors.
Related Issues (20)
- [Feature request] A more powerful custom origin calculation method depending on other headers HOT 6
- No Configuration Options for Access-Control-Allow-Private-Network HOT 1
- CORS Error only on Mac HOT 2
- Cors origin RegExp issues HOT 10
- Option preflightContinue not working with origin function
- Array - set origin -Not working HOT 3
- Incorrect response when option origin is true and requestOrigin is undefined HOT 2
- "origin" is undefined when requests are received from the same server AND when malicious requests are sent from a program HOT 1
- Undefined origin should be treated as not allowed - discusson HOT 4
- Configure Allowed Headers as Array of RegExp
- DEMO is broken HOT 1
- Invalid Vary header in Access-Control-Allow-Headers HOT 2
- `OPTIONS` request handler missing `Allow` header HOT 13
- cors is hanging HOT 2
- CORS error when fonts
- Add support for having specified domain instead of wildcard HOT 3
- Request: callback for failed CORS HOT 5
- Cors error when connecting through ssh tunnel HOT 1
- I have random 'Access-Control-Allow-Origin' errors, even if i set origin: '*', is my usage correct ? HOT 3
- Add ability to omit `Vary: Origin` header HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from cors.