Vitali
04/29/2022, 5:33 PMVitali
04/29/2022, 5:37 PMErisa | Support Engineer
04/29/2022, 5:37 PMhttps://r2-test.erisa.workers.dev/Discord_ymAP8uWin1.png▾
Erisa | Support Engineer
04/29/2022, 5:37 PMErisa | Support Engineer
04/29/2022, 5:42 PMhttps://cdn.erisa.uk/bLXT1wEKT4.png▾
kavinplays
04/29/2022, 5:44 PMErisa | Support Engineer
04/29/2022, 5:44 PMkavinplays
04/29/2022, 5:44 PMErisa | Support Engineer
04/29/2022, 5:45 PMkavinplays
04/29/2022, 5:45 PMErisa | Support Engineer
04/29/2022, 5:45 PMsean
04/29/2022, 5:46 PMIsaac McFadyen | YYZ01
04/29/2022, 5:47 PMErisa | Support Engineer
04/29/2022, 5:48 PMErisa | Support Engineer
04/29/2022, 5:49 PMErisa | Support Engineer
04/29/2022, 5:49 PMjohn.spurlock
04/29/2022, 5:50 PMIsaac McFadyen | YYZ01
04/29/2022, 5:50 PMlmtr0
04/29/2022, 5:51 PMVitali
04/29/2022, 5:51 PMAccess-Control-Allow-Headers: *
fails open or closed?Isaac McFadyen | YYZ01
04/29/2022, 5:52 PMAccess-Control-Allow-Headers: *
says that a fetch request from any site can access stuff.lmtr0
04/29/2022, 5:52 PM<bucket>.<account>.cloudflare.....
? if not, then I found the problem....sean
04/29/2022, 5:52 PMIsaac McFadyen | YYZ01
04/29/2022, 5:52 PMIsaac McFadyen | YYZ01
04/29/2022, 5:53 PMAccess-Control-Allow-Origin: *
if it allows any site to be able to do requests
- Browser sends actual request (GET/POST/PUT/etc)
- Server returns Access-Control-Allow-Origin: *
to indicate that the browser is allowed to read the response.Isaac McFadyen | YYZ01
04/29/2022, 5:53 PMexample.com
which means that only requests from the example.com
Javascript are allowed.john.spurlock
04/29/2022, 5:55 PMIsaac McFadyen | YYZ01
04/29/2022, 5:55 PMAccess-Control-Allow-Headers: *
to allow amz- headers and Access-Control-Allow-Origin: *
to allow all origins.Isaac McFadyen | YYZ01
04/29/2022, 5:55 PMAccess-Control-Allow-Origin: *