[NEW] Add Allow Methods directive to CORS (#13073)

pull/13091/head
Marcos Spessatto Defendi 7 years ago committed by Diego Sampaio
parent b0b79f39a4
commit 3c8ae75202
  1. 1
      packages/rocketchat-api/server/api.js

@ -386,6 +386,7 @@ const defaultOptionsEndpoint = function _defaultOptionsEndpoint() {
if (RocketChat.settings.get('API_Enable_CORS') === true) {
this.response.writeHead(200, {
'Access-Control-Allow-Origin': RocketChat.settings.get('API_CORS_Origin'),
'Access-Control-Allow-Methods': 'GET, POST, PUT, DELETE, HEAD, PATCH',
'Access-Control-Allow-Headers': 'Origin, X-Requested-With, Content-Type, Accept, X-User-Id, X-Auth-Token, x-visitor-token',
});
} else {

Loading…
Cancel
Save