mirror of https://github.com/pixelfed/pixelfed
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
68 lines
1.8 KiB
PHP
68 lines
1.8 KiB
PHP
<?php
|
|
|
|
return [
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Laravel CORS Options
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| The allowed_methods and allowed_headers options are case-insensitive.
|
|
|
|
|
| You don't need to provide both allowed_origins and allowed_origins_patterns.
|
|
| If one of the strings passed matches, it is considered a valid origin.
|
|
|
|
|
| If array('*') is provided to allowed_methods, allowed_origins or allowed_headers
|
|
| all methods / origins / headers are allowed.
|
|
|
|
|
*/
|
|
|
|
/*
|
|
* You can enable CORS for 1 or multiple paths.
|
|
* Example: ['api/*']
|
|
*/
|
|
'paths' => [
|
|
'.well-known/*',
|
|
'api/*',
|
|
'oauth/*',
|
|
'sanctum/csrf-cookie',
|
|
'login',
|
|
'logout',
|
|
],
|
|
|
|
/*
|
|
* Matches the request method. `[*]` allows all methods.
|
|
*/
|
|
'allowed_methods' => ['*'],
|
|
|
|
/*
|
|
* Matches the request origin. `[*]` allows all origins. Wildcards can be used, eg `*.mydomain.com`
|
|
*/
|
|
'allowed_origins' => env('PF_CORS_ALLOWED_ORIGINS') ? explode(',', env('PF_CORS_ALLOWED_ORIGINS', '')) : [],
|
|
|
|
/*
|
|
* Patterns that can be used with `preg_match` to match the origin.
|
|
*/
|
|
'allowed_origins_patterns' => [],
|
|
|
|
/*
|
|
* Sets the Access-Control-Allow-Headers response header. `[*]` allows all headers.
|
|
*/
|
|
'allowed_headers' => ['*'],
|
|
|
|
/*
|
|
* Sets the Access-Control-Expose-Headers response header with these headers.
|
|
*/
|
|
'exposed_headers' => ['Link', 'X-RateLimit-Limit', 'X-RateLimit-Remaining'],
|
|
|
|
/*
|
|
* Sets the Access-Control-Max-Age response header when > 0.
|
|
*/
|
|
'max_age' => 0,
|
|
|
|
/*
|
|
* Sets the Access-Control-Allow-Credentials header.
|
|
*/
|
|
'supports_credentials' => true,
|
|
];
|