mirror of
https://github.com/prometheus/prometheus.git
synced 2024-12-28 06:59:40 -08:00
Disallow cross-origin DELETE and POST requests.
This commit is contained in:
parent
364003c444
commit
bc1c789bab
|
@ -65,7 +65,7 @@ type API struct {
|
||||||
// Enables cross-site script calls.
|
// Enables cross-site script calls.
|
||||||
func setCORS(w http.ResponseWriter) {
|
func setCORS(w http.ResponseWriter) {
|
||||||
w.Header().Set("Access-Control-Allow-Headers", "Accept, Authorization, Content-Type, Origin")
|
w.Header().Set("Access-Control-Allow-Headers", "Accept, Authorization, Content-Type, Origin")
|
||||||
w.Header().Set("Access-Control-Allow-Methods", "GET, POST, DELETE")
|
w.Header().Set("Access-Control-Allow-Methods", "GET")
|
||||||
w.Header().Set("Access-Control-Allow-Origin", "*")
|
w.Header().Set("Access-Control-Allow-Origin", "*")
|
||||||
w.Header().Set("Access-Control-Expose-Headers", "Date")
|
w.Header().Set("Access-Control-Expose-Headers", "Date")
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in a new issue