Add the Origin from the requests to the Access-Control-Allow-Origin header in the response

Viewed 35

I'd like to allow all origins to fetch resources from my apache server.

Instead of adding:

Access-Control-Allow-Origin: *

I would like my server to craft a special response with :

Access-Control-Allow-Origin: <the value of the Origin received in the request>

Is there something I can add to httpd.conf to achieve this ?

1 Answers

Seems it can be achieved by adding those two lines:

SetEnvIf Origin ".*\S.*" ORIGIN=$0
Header always set Access-Control-Allow-Origin %{ORIGIN}e env=ORIGIN

The regex pretty much means anything except newline, tab, and space, so as long as the Origin is not empty add it to the response header.

Related