Skip to content
This repository was archived by the owner on Apr 26, 2024. It is now read-only.

Commit 27c06a6

Browse files
Drop Origin & Accept from Access-Control-Allow-Headers value (#10114)
* Drop Origin & Accept from Access-Control-Allow-Headers value This change drops the Origin and Accept header names from the value of the Access-Control-Allow-Headers response header sent by Synapse. Per the CORS protocol, it’s not necessary or useful to include those header names. Details: Per-spec at https://fetch.spec.whatwg.org/#forbidden-header-name, Origin is a “forbidden header name” set by the browser and that frontend JavaScript code is never allowed to set. So the value of Access-Control-Allow-Headers isn’t relevant to Origin or in general to other headers set by the browser itself — the browser never ever consults the Access-Control-Allow-Headers value to confirm that it’s OK for the request to include an Origin header. And per-spec at https://fetch.spec.whatwg.org/#cors-safelisted-request-header, Accept is a “CORS-safelisted request-header”, which means that browsers allow requests to contain the Accept header regardless of whether the Access-Control-Allow-Headers value contains "Accept". So it’s unnecessary for the Access-Control-Allow-Headers to explicitly include Accept. Browsers will not perform a CORS preflight for requests containing an Accept request header. Related: matrix-org/matrix-spec-proposals#3225 Signed-off-by: Michael[tm] Smith <[email protected]>
1 parent 33701dc commit 27c06a6

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

changelog.d/10114.misc

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Drop Origin and Accept from the value of the Access-Control-Allow-Headers response header.

synapse/http/server.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -728,7 +728,7 @@ def set_cors_headers(request: Request):
728728
)
729729
request.setHeader(
730730
b"Access-Control-Allow-Headers",
731-
b"Origin, X-Requested-With, Content-Type, Accept, Authorization, Date",
731+
b"X-Requested-With, Content-Type, Authorization, Date",
732732
)
733733

734734

0 commit comments

Comments
 (0)