Commit d789729
Expose WWW-Authenticate and X-Request-ID in CORS headers (v0.6.2)
Browsers cannot read non-safelisted response headers from cross-origin
responses unless they appear in Access-Control-Expose-Headers. Always
expose WWW-Authenticate (needed for OAuth discovery from 401 responses)
and X-Request-ID (for client-side debugging) when CORS is enabled.
Also allow Authorization in request headers for Bearer token support.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 90ce155 commit d789729
3 files changed
Lines changed: 6 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
85 | 85 | | |
86 | 86 | | |
87 | 87 | | |
88 | | - | |
| 88 | + | |
| 89 | + | |
89 | 90 | | |
90 | 91 | | |
91 | 92 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
316 | 316 | | |
317 | 317 | | |
318 | 318 | | |
| 319 | + | |
319 | 320 | | |
320 | 321 | | |
321 | 322 | | |
| |||
329 | 330 | | |
330 | 331 | | |
331 | 332 | | |
| 333 | + | |
| 334 | + | |
332 | 335 | | |
333 | 336 | | |
334 | 337 | | |
| |||
0 commit comments