w3c recommends detecting the client origin and echoing it back to them if it matches ours.

This commit is contained in:
Ralph Bean 2015-08-18 04:24:21 +00:00
parent 0245b760f8
commit ee4c97bab4

View file

@ -2,8 +2,8 @@ Alias /static /usr/lib/python2.7/site-packages/bodhi/static/
<Directory /usr/lib/python2.7/site-packages/bodhi/static>
# modern browsers require that fonts have this
Header set Access-Control-Allow-Origin "https://*.fedoraproject.org"
Header set Access-Control-Allow-Origin "http://*.fedoraproject.org"
SetEnvIf Origin "^http(s)?://(.+\.)?fedoraproject\.org$" AccessControlAllowOrigin=$0
Header set Access-Control-Allow-Origin %{AccessControlAllowOrigin} env=AccessControlAllowOrigin
</Directory>
WSGIDaemonProcess bodhi user=bodhi group=bodhi display-name=bodhi processes={{wsgi_procs}} threads={{wsgi_threads}}