Skip to content

Commit 4957840

Browse files
committed
Omit non-credentialed CORS header
1 parent 6e9e52a commit 4957840

2 files changed

Lines changed: 1 addition & 3 deletions

File tree

src/nodenorm/handlers/base.py

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,6 @@ class NodeNormalizationBaseHandler(BaseHandler):
77
"""Base handler that keeps the lightweight BioThings handler plus CORS."""
88

99
cors_origin = "*"
10-
cors_allow_credentials = "false"
1110
cors_methods = "GET, POST, HEAD, OPTIONS"
1211
cors_max_age = "600"
1312

@@ -19,7 +18,6 @@ def set_default_headers(self):
1918
requested_headers = self.request.headers.get("Access-Control-Request-Headers")
2019

2120
self.set_header("Access-Control-Allow-Origin", self.cors_origin)
22-
self.set_header("Access-Control-Allow-Credentials", self.cors_allow_credentials)
2321
self.set_header("Access-Control-Allow-Methods", self.cors_methods)
2422
self.set_header("Access-Control-Allow-Headers", requested_headers or "*")
2523
self.set_header("Access-Control-Max-Age", self.cors_max_age)

tests/test_cors.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ async def get(self):
1313

1414
def assert_cors_headers(headers, allowed_headers="*"):
1515
assert headers["Access-Control-Allow-Origin"] == "*"
16-
assert headers["Access-Control-Allow-Credentials"] == "false"
16+
assert "Access-Control-Allow-Credentials" not in headers
1717
assert headers["Access-Control-Allow-Methods"] == "GET, POST, HEAD, OPTIONS"
1818
assert headers["Access-Control-Allow-Headers"] == allowed_headers
1919
assert headers["Access-Control-Max-Age"] == "600"

0 commit comments

Comments
 (0)