From 056b83e32c7cd24182c36d0b27f9f5a03c50ee1d Mon Sep 17 00:00:00 2001 From: Joakim Olsson Date: Tue, 26 Oct 2021 11:04:30 +0200 Subject: [PATCH] fix: hide proxy headers for CORS --- nginx.conf | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/nginx.conf b/nginx.conf index 322b94a..e7e6a3f 100644 --- a/nginx.conf +++ b/nginx.conf @@ -86,6 +86,12 @@ http { proxy_set_header Authorization $authorization; proxy_hide_header x-amz-id-2; proxy_hide_header x-amz-request-id; + proxy_hide_header 'Access-Control-Expose-Headers'; + proxy_hide_header 'Access-Control-Allow-Origin'; + proxy_hide_header 'Access-Control-Allow-Credentials'; + proxy_hide_header 'Access-Control-Allow-Methods'; + proxy_hide_header 'Access-Control-Allow-Headers'; + proxy_hide_header 'Access-Control-Max-Age'; add_header X-File-URL $returnurl; resolver 8.8.8.8 valid=300s; @@ -153,6 +159,12 @@ http { proxy_set_header Authorization $authorization; proxy_hide_header x-amz-id-2; proxy_hide_header x-amz-request-id; + proxy_hide_header 'Access-Control-Expose-Headers'; + proxy_hide_header 'Access-Control-Allow-Origin'; + proxy_hide_header 'Access-Control-Allow-Credentials'; + proxy_hide_header 'Access-Control-Allow-Methods'; + proxy_hide_header 'Access-Control-Allow-Headers'; + proxy_hide_header 'Access-Control-Max-Age'; add_header X-File-URL $returnurl; resolver 8.8.8.8 valid=300s;