-
-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Closed
Labels
corsCross-Origin Resource SharingCross-Origin Resource Sharinggood first issueGood for beginnersGood for beginnershelp wantedFeel free to helpFeel free to help
Milestone
Description
Discussed in #1823
Originally posted by gyusang August 26, 2022
When sending a CORS request with credentials, wildcard origin is rejected by the standard.
The CORS middleware handles this case when cookies are included, but is missing the case when Authorization header is present.
https://github.com/encode/starlette/blob/31164e346b9bd1ce17d968e1301c3bb2c23bb418/starlette/middleware/cors.py#L164-L165
Since Token authentication is also widely used these days, I believe explicit header should be returned when Authorization header is present.
Important
- We're using Polar.sh so you can upvote and help fund this issue.
- We receive the funding once the issue is completed & confirmed by you.
- Thank you in advance for helping prioritize & fund our backlog.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
corsCross-Origin Resource SharingCross-Origin Resource Sharinggood first issueGood for beginnersGood for beginnershelp wantedFeel free to helpFeel free to help