The documentation around CORS headers for amp-forms could be easier, and I'm still a bit of a loss whether I've done everything right.
Right now, my form appears to work from my own website as well as from Google's AMP result. It doesn't work from my development website, though; and I'm also not sure whether it is really very secure. Here is the code I'm using so far, to a script that lives on https://podnews.net
This has been the result of a lot of trial and error, and I can't help thinking that the documentation could be much clearer around this issue.
header('Cache-Control: private, no-cache');
header('Access-Control-Allow-Origin: '.$_SERVER['HTTP_ORIGIN']);
header('Access-Control-Allow-Credentials: true');
header('access-control-expose-headers: AMP-Access-Control-Allow-Source-Origin');
header('AMP-Access-Control-Allow-Source-Origin: https://podnews.net');
header('Content-Type: application/json');
Particularly: $_SERVER['HTTP_ORIGIN'] can include AMP caches, as I understand it.
What are the correct valid values here? How can I add more than one value (given there are at least two AMP caches out there)? Why isn't it working on the development site, which is something like http://dev.podnews.net (the error it kicks up is the CORS one, not one about being in HTTP not HTTPS). How can I write this up so that all AMP developers have an easy reference?