From 3c8ae752027fdde31fe6a40af53a64caa4e87de0 Mon Sep 17 00:00:00 2001 From: Marcos Spessatto Defendi Date: Tue, 8 Jan 2019 10:36:02 -0200 Subject: [PATCH] [NEW] Add Allow Methods directive to CORS (#13073) --- packages/rocketchat-api/server/api.js | 1 + 1 file changed, 1 insertion(+) diff --git a/packages/rocketchat-api/server/api.js b/packages/rocketchat-api/server/api.js index d28a95d95f4..ff10ec4a4b1 100644 --- a/packages/rocketchat-api/server/api.js +++ b/packages/rocketchat-api/server/api.js @@ -386,6 +386,7 @@ const defaultOptionsEndpoint = function _defaultOptionsEndpoint() { if (RocketChat.settings.get('API_Enable_CORS') === true) { this.response.writeHead(200, { 'Access-Control-Allow-Origin': RocketChat.settings.get('API_CORS_Origin'), + 'Access-Control-Allow-Methods': 'GET, POST, PUT, DELETE, HEAD, PATCH', 'Access-Control-Allow-Headers': 'Origin, X-Requested-With, Content-Type, Accept, X-User-Id, X-Auth-Token, x-visitor-token', }); } else {