Security: CORS allow_headers enthält kein Authorization #2
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem\n\n
server.py:76—allow_headers=["Content-Type"]fehltAuthorization.\n\nSobald die App über eine andere Origin aufgerufen wird (z.B. VCH-Subdomain-Wechsel), schlagen alleapiFetch()-Calls mit Bearer-Token still fehl — der Browser blockiert den CORS-Preflight.\n\n## Fix\n\npython\nallow_headers=["Content-Type", "Authorization"]\nFixed in commit
be0a790.