GWM : CORS error handling

This commit is contained in:
Gowtham M 2025-11-30 11:10:54 +05:30
parent c67879b970
commit 1cdac27388
2 changed files with 9 additions and 36 deletions

View File

@ -61,6 +61,7 @@ class Filters extends BaseFilters
'before' => [ 'before' => [
'forcehttps', // Force Global Secure Requests 'forcehttps', // Force Global Secure Requests
'pagecache', // Web Page Caching 'pagecache', // Web Page Caching
], ],
'after' => [ 'after' => [
'pagecache', // Web Page Caching 'pagecache', // Web Page Caching
@ -80,6 +81,7 @@ class Filters extends BaseFilters
// 'honeypot', // 'honeypot',
// 'csrf', // 'csrf',
// 'invalidchars', // 'invalidchars',
'cors'
], ],
'after' => [ 'after' => [
// 'honeypot', // 'honeypot',

View File

@ -2,53 +2,24 @@
namespace App\Filters; namespace App\Filters;
use CodeIgniter\Filters\FilterInterface;
use CodeIgniter\HTTP\RequestInterface; use CodeIgniter\HTTP\RequestInterface;
use CodeIgniter\HTTP\ResponseInterface; use CodeIgniter\HTTP\ResponseInterface;
use CodeIgniter\Filters\FilterInterface;
class Cors implements FilterInterface class Cors implements FilterInterface
{ {
/**
* Do whatever processing this filter needs to do.
* By default it should not return anything during
* normal execution. However, when an abnormal state
* is found, it should return an instance of
* CodeIgniter\HTTP\Response. If it does, script
* execution will end and that Response will be
* sent back to the client, allowing for error pages,
* redirects, etc.
*
* @param RequestInterface $request
* @param array|null $arguments
*
* @return RequestInterface|ResponseInterface|string|void
*/
public function before(RequestInterface $request, $arguments = null) public function before(RequestInterface $request, $arguments = null)
{ {
// Set CORS headers header('Access-Control-Allow-Origin: *'); // or your domain
header("Access-Control-Allow-Origin: *"); header('Access-Control-Allow-Headers: Content-Type, Authorization, X-Requested-With');
header("Access-Control-Allow-Methods: GET, POST, OPTIONS, PUT, DELETE"); header('Access-Control-Allow-Methods: GET, POST, OPTIONS, PUT, DELETE');
header("Access-Control-Allow-Headers: Content-Type, Authorization, X-Requested-With");
// Handle preflight requests // Handle preflight OPTIONS request
if ($_SERVER['REQUEST_METHOD'] === 'OPTIONS') { if ($request->getMethod() === 'options') {
header("HTTP/1.1 200 OK"); die();
exit;
} }
} }
/**
* Allows After filters to inspect and modify the response
* object as needed. This method does not allow any way
* to stop execution of other after filters, short of
* throwing an Exception or Error.
*
* @param RequestInterface $request
* @param ResponseInterface $response
* @param array|null $arguments
*
* @return ResponseInterface|void
*/
public function after(RequestInterface $request, ResponseInterface $response, $arguments = null) public function after(RequestInterface $request, ResponseInterface $response, $arguments = null)
{ {
return $response; return $response;