diff --git a/src/Application/ResponseEmitter/ResponseEmitter.php b/src/Application/ResponseEmitter/ResponseEmitter.php index a594062..3059666 100644 --- a/src/Application/ResponseEmitter/ResponseEmitter.php +++ b/src/Application/ResponseEmitter/ResponseEmitter.php @@ -17,13 +17,27 @@ class ResponseEmitter extends SlimResponseEmitter // This variable should be set to the allowed host from which your API can be accessed with $origin = $_SERVER['HTTP_ORIGIN'] ?? ''; + $allowedHeaders = implode(', ', [ + 'X-Requested-With', + 'Content-Type', + 'Accept', + 'Origin', + 'Authorization', + 'DNT', + 'Keep-Alive', + 'User-Agent', + 'If-Modified-Since', + 'Cache-Control', + 'Range', + 'DPoP', + 'atproto-accept-labelers', + 'atproto-proxy', + ]); + $response = $response ->withHeader('Access-Control-Allow-Credentials', 'true') ->withHeader('Access-Control-Allow-Origin', $origin) - ->withHeader( - 'Access-Control-Allow-Headers', - 'X-Requested-With, Content-Type, Accept, Origin, Authorization, DNT, Keep-Alive, User-Agent, If-Modified-Since, Cache-Control, Content-Type, Range, DPoP, atproto-accept-labelers, atproto-proxy', - ) + ->withHeader('Access-Control-Allow-Headers', $allowedHeaders) ->withHeader('Access-Control-Expose-Headers', 'DPoP-Nonce') ->withHeader('Access-Control-Allow-Methods', 'GET, POST, PUT, PATCH, DELETE, OPTIONS') ->withHeader('Cache-Control', 'no-store, no-cache, must-revalidate, max-age=0')