Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove null 'Access-Control-Allow-Origin' if origin check has failed #131

Merged
merged 3 commits into from Nov 6, 2019

Conversation

@prosalov
Copy link
Contributor

prosalov commented Jul 26, 2019

Hey. Just a security improvement. It seems like if a request Origin is not allowed, Access-Control-Allow-Origin shouldn't be returned in a response.

https://w3c.github.io/webappsec-cors-for-developers/#avoid-returning-access-control-allow-origin-null

@Seldaek Seldaek merged commit 1f20109 into nelmio:master Nov 6, 2019
1 check failed
1 check failed
continuous-integration/travis-ci/pr The Travis CI build failed
Details
@Seldaek

This comment has been minimized.

Copy link
Member

Seldaek commented Nov 6, 2019

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
3 participants
You can’t perform that action at this time.