I am developing a VS Code extension that needs to query various NuGet API's including private ones. I want to allow the user to provide an Authorization header that I will use to call these private API's.
I am having issues with the GitHub NuGet API because the browser is making a preflight OPTIONS request to the API to check for CORS. I know this is intended and normal when you include an Authorization header. My issue is that the GitHub API does not return a "access-control-allow-headers: authorization" header. So the Browser is blocking my request, as I think it should.
Am I missing something here or is the GitHub API improperly implemented? Any help, ideas are greatly appreciated.
The code that is making these requests can be seen here on Github. Or just the request part here:
this.http
.get<ApiIndexResponse>(sourceUrl, {
headers: requestHeaders,
}) // where requestHeaders is a normal "Bearer token" header, so nothing special

