浏览代码

Use weak CORS policy for experimental_no_subdomain

KernelDeimos 1 年之前
父节点
当前提交
343edbff51
共有 1 个文件被更改,包括 4 次插入1 次删除
  1. 4 1
      packages/backend/src/services/WebServerService.js

+ 4 - 1
packages/backend/src/services/WebServerService.js

@@ -291,7 +291,10 @@ class WebServerService extends BaseService {
                 res.setHeader('Access-Control-Allow-Origin', origin ?? '*');
             }
             // Website(s) to allow to connect
-            if ( req.subdomains[req.subdomains.length-1] === 'api' ) {
+            if (
+                config.experimental_no_subdomain ||
+                req.subdomains[req.subdomains.length-1] === 'api'
+            ) {
                 res.setHeader('Access-Control-Allow-Origin', origin ?? '*');
                 res.setHeader('Access-Control-Allow-Credentials', 'true');
             }