Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

11
  • It will allow it to read the response since the Access-Control-Allow-Origin: header is set. Commented Jun 8, 2015 at 16:38
  • Shouldn't the requesting resource's origin match the one set for Access-Control-Allow-Origin for it to read the resource? Commented Jun 8, 2015 at 16:56
  • Yes, but that was what the posted code was doing: header("Access-Control-Allow-Origin: " . $_SERVER["HTTP_ORIGIN"]); Commented Jun 8, 2015 at 16:59
  • Ah, you are right. I misread the second question. Thank you. Commented Jun 8, 2015 at 17:09
  • 1
    @Vallentin To me it seems that you would need to read the response to get the token, which also u seem to allow with access-control headers. If u had any sort of cookie based authentication, that would help as u cannot set access-control to a * with 'allow credentials' set to true. Commented Aug 26, 2015 at 12:54