Refactor VK service URLs to use 'vk.ru' instead of 'vk.com' for consistency; update CORS configuration to allow additional methods and origins, enhancing API security and flexibility.
This commit is contained in:
+14
-18
@@ -2,23 +2,19 @@
|
||||
|
||||
return [
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Cross-Origin Resource Sharing (CORS) Configuration
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Here you may configure your settings for cross-origin resource sharing
|
||||
| or "CORS". This determines what cross-origin operations may execute
|
||||
| in web browsers. You are free to adjust these settings as needed.
|
||||
|
|
||||
| To learn more: https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS
|
||||
|
|
||||
*/
|
||||
'paths' => ['api/*'],
|
||||
|
||||
'allowed_methods' => ['GET', 'POST', 'PUT', 'DELETE'],
|
||||
|
||||
'allowed_origins' => explode(',', env('CORS_ALLOWED_ORIGINS', 'https://www.ntspi.ru')),
|
||||
|
||||
'allowed_origins_patterns' => [],
|
||||
|
||||
'allowed_headers' => ['Content-Type', 'X-Requested-With', 'Authorization'],
|
||||
|
||||
'exposed_headers' => [],
|
||||
|
||||
'max_age' => 3600,
|
||||
|
||||
'allowed_origins' => ['http://localhost', 'http://127.0.0.1'],
|
||||
'allowed_methods' => ['GET', 'POST'],
|
||||
'allowed_headers' => ['Content-Type', 'Authorization'],
|
||||
'supports_credentials' => true,
|
||||
|
||||
|
||||
];
|
||||
];
|
||||
Reference in New Issue
Block a user