| Summary: | CrossOriginFilter does not send Access-Control-Allow-Origin on responses | ||
|---|---|---|---|
| Product: | [RT] Jetty | Reporter: | Damien <damien.feugas> |
| Component: | server | Assignee: | Simone Bordet <simone.bordet> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | P3 | CC: | calvinkrishy, jetty-inbox |
| Version: | 7.1.3 | ||
| Target Milestone: | 7.1.x | ||
| Hardware: | All | ||
| OS: | All | ||
| Whiteboard: | |||
|
Description
Damien
Simone, can you look at this one, as I find the specification document a bit impenetrable and you've already looked at it so you may have better understanding than I. The spec appears to distinguish behaviour for simple requests, actual requests and preflight request. However the filter appears to assume that any non simple requests are preflight requests. It would also be good to have a test harness for this filter. cheers Fixed in Jetty 7. Now actual responses contain the Access-Control-Allow-Origin header. *** Bug 365746 has been marked as a duplicate of this bug. *** |