diff options
-rw-r--r-- | external/newsapi.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/external/newsapi.php b/external/newsapi.php index 2b250f5b4..4a463ec9e 100644 --- a/external/newsapi.php +++ b/external/newsapi.php @@ -80,7 +80,7 @@ class NewsAPI extends Controller { public function cors() { // needed for webapps access due to cross origin request policy $response = new Response(); - $response->addHeader('Access-Control-Allow-Origin', '*'); + $response->addHeader('Access-Control-Allow-Origin', $request->server['Origin']); $response->addHeader('Access-Control-Allow-Methods', 'PUT, POST, GET, DELETE'); $response->addHeader('Access-Control-Allow-Credentials', 'true'); $response->addHeader('Access-Control-Allow-Headers', 'Authorization, Content-Type'); |