1
1
set $request_cors "${request_method}_${CORS_ENABLED}";
2
2
3
3
if ($request_cors = "OPTIONS_1") {
4
- add_header 'Access-Control-Allow-Origin' '* ';
4
+ add_header 'Access-Control-Allow-Origin' '${CORS_ALLOWED_ORIGIN} ';
5
5
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
6
6
#
7
7
# Custom headers and headers various browsers *should* be OK with but aren't
@@ -17,14 +17,14 @@ if ($request_cors = "OPTIONS_1") {
17
17
}
18
18
19
19
if ($request_cors = "GET_1") {
20
- add_header 'Access-Control-Allow-Origin' '* ' always;
20
+ add_header 'Access-Control-Allow-Origin' '${CORS_ALLOWED_ORIGIN} ' always;
21
21
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS' always;
22
22
add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range' always;
23
23
add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range' always;
24
24
}
25
25
26
26
if ($request_cors = "HEAD_1") {
27
- add_header 'Access-Control-Allow-Origin' '* ' always;
27
+ add_header 'Access-Control-Allow-Origin' '${CORS_ALLOWED_ORIGIN} ' always;
28
28
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS' always;
29
29
add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range' always;
30
30
add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range' always;
0 commit comments