We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent c7feb52 commit 073cc87Copy full SHA for 073cc87
src/CorsService.php
@@ -145,8 +145,8 @@ private function configureAllowedOrigin(Response $response, Request $request)
145
// Single origins can be safely set
146
$response->headers->set('Access-Control-Allow-Origin', array_values($this->options['allowedOrigins'])[0]);
147
} else {
148
- // For dynamic headers, check the origin first
149
- if ($request->headers->has('Origin') && $this->isOriginAllowed($request)) {
+ // For dynamic headers, set the requested Origin header when set and allowed
+ if ($this->isCorsRequest($request) && $this->isOriginAllowed($request)) {
150
$response->headers->set('Access-Control-Allow-Origin', $request->headers->get('Origin'));
151
}
152
0 commit comments