FEATURE: Add Content-Type header to CORS

- add Content-Type to Access-Control-Allow-Headers
- update test accordingly
This commit is contained in:
Davide Porrovecchio
2018-08-28 03:19:38 +02:00
committed by Sam
parent ebe7835316
commit 1826626272
2 changed files with 2 additions and 2 deletions

View File

@@ -107,7 +107,7 @@ describe Hijack do
expected = {
"Access-Control-Allow-Origin" => "www.rainbows.com",
"Access-Control-Allow-Headers" => "X-Requested-With, X-CSRF-Token, Discourse-Visible, User-Api-Key, User-Api-Client-Id",
"Access-Control-Allow-Headers" => "Content-Type, X-Requested-With, X-CSRF-Token, Discourse-Visible, User-Api-Key, User-Api-Client-Id",
"Access-Control-Allow-Credentials" => "true"
}