Fixed cross domain middleware not exposing the Authorization header

This commit is contained in:
Alejandro Celaya 2016-08-27 13:00:41 +02:00
parent 924ba58f73
commit 4bd67d5f98

View file

@ -41,7 +41,8 @@ class CrossDomainMiddleware implements MiddlewareInterface
}
// Add Allow-Origin header
$response = $response->withHeader('Access-Control-Allow-Origin', $request->getHeader('Origin'));
$response = $response->withHeader('Access-Control-Allow-Origin', $request->getHeader('Origin'))
->withHeader('Access-Control-Expose-Headers', 'Authorization');
if ($request->getMethod() !== 'OPTIONS') {
return $response;
}