whitelist OPTIONS requests?

24 wyświetlenia
Przejdź do pierwszej nieodczytanej wiadomości

Jonathan Price

nieprzeczytany,
20 sty 2015, 21:27:5720.01.2015
do taffy...@googlegroups.com
Do you guys tend to do this, or should I treat it with the same authentication requirements (i.e. a request token) as other verbs?

Adam Tuttle

nieprzeczytany,
21 sty 2015, 11:21:0921.01.2015
do taffy...@googlegroups.com
If it's an AJAX CORS options request, then it should contain the authentication information anyway: that's half the point of the request ("if I changed the verb to {verb}, would this work? also what are acceptable verbs and headers at this URI?")

So my gut says you should enforce the same auth rules for options requests. If the options request fails, it means the following request would fail too.

Adam

On Tue, Jan 20, 2015 at 9:27 PM, Jonathan Price <purit...@gmail.com> wrote:
Do you guys tend to do this, or should I treat it with the same authentication requirements (i.e. a request token) as other verbs?

--
You received this message because you are subscribed to the Google Groups "Taffy Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to taffy-users...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Puritan Paul

nieprzeczytany,
21 sty 2015, 17:27:2321.01.2015
do taffy...@googlegroups.com
Makes sense to me.  I'm having trouble getting Angular to include it in the headers for OPTIONS, and this was my lazy workaround. Thanks.



You received this message because you are subscribed to a topic in the Google Groups "Taffy Users" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/taffy-users/ivYrcTNsKqs/unsubscribe.
To unsubscribe from this group and all its topics, send an email to taffy-users...@googlegroups.com.
Odpowiedz wszystkim
Odpowiedz autorowi
Przekaż
Nowe wiadomości: 0