@@ -45,6 +45,10 @@ corsPolicy req = case lookup "origin" headers of
|
|||||||
Just origin -> Just defaultCorsPolicy {
|
Just origin -> Just defaultCorsPolicy {
|
||||||
corsOrigins = Just ([origin], True)
|
corsOrigins = Just ([origin], True)
|
||||||
, corsRequestHeaders = "Authentication":accHeaders
|
, corsRequestHeaders = "Authentication":accHeaders
|
||||||
|
, corsExposedHeaders = Just [
|
||||||
|
"Content-Encoding", "Content-Location", "Content-Range", "Content-Type"
|
||||||
|
, "Date", "Server", "Transfer-Encoding", "Range-Unit"
|
||||||
|
]
|
||||||
}
|
}
|
||||||
Nothing -> Nothing
|
Nothing -> Nothing
|
||||||
where
|
where
|
||||||
|
|||||||
@@ -53,6 +53,14 @@ spec = around withApp $ describe "CORS" $ do
|
|||||||
r <- request methodOptions "/" preflightHeaders ""
|
r <- request methodOptions "/" preflightHeaders ""
|
||||||
liftIO $ simpleBody r `shouldBe` ""
|
liftIO $ simpleBody r `shouldBe` ""
|
||||||
|
|
||||||
|
describe "regular request" $
|
||||||
|
it "exposes necesssary response headers" $ do
|
||||||
|
r <- request methodGet "/items" [("Origin", "http://example.com")] ""
|
||||||
|
liftIO $ simpleHeaders r `shouldSatisfy` matchHeader
|
||||||
|
"Access-Control-Expose-Headers"
|
||||||
|
"Content-Encoding, Content-Location, Content-Range, Content-Type, \
|
||||||
|
\Date, Server, Transfer-Encoding, Range-Unit"
|
||||||
|
|
||||||
describe "postflight request" $
|
describe "postflight request" $
|
||||||
it "allows INFO body through even with CORS request headers present" $ do
|
it "allows INFO body through even with CORS request headers present" $ do
|
||||||
r <- request methodOptions "/items" normalCors ""
|
r <- request methodOptions "/items" normalCors ""
|
||||||
|
|||||||
Reference in New Issue
Block a user