Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-3994

CORS filter looks at too many headers

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Not A Problem
    • 2.5.1
    • 2.5.1
    • JAX-RS
    • None
    • Unknown

    Description

      The org.apache.cxf.jaxrs.cors.CrossOriginResourceSharingFilter should not look at 'agent headers' such as Origin or Cookies. Currently, it looks at them, and will reject a preflight one isn't listed in the list of permitted headers.

      Attachments

        Activity

          People

            bmargulies Benson Margulies
            bmargulies Benson Margulies
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: