fix(admin): isolate login on admin host
Allow runtime request headers through API preflight and keep the storefront shell hidden while admin QR authentication gates backoffice.
This commit is contained in:
@@ -59,7 +59,7 @@ server {
|
||||
add_header Access-Control-Allow-Origin \$cors_origin always;
|
||||
add_header Access-Control-Allow-Credentials "true" always;
|
||||
add_header Access-Control-Allow-Methods "GET, POST, PUT, PATCH, DELETE, OPTIONS" always;
|
||||
add_header Access-Control-Allow-Headers "Authorization, Content-Type, AdminWebSessionID, X-Requested-With" always;
|
||||
add_header Access-Control-Allow-Headers "Authorization, Content-Type, AdminWebSessionID, WebSessionID, Currency, X-Language, X-Region, X-Requested-With" always;
|
||||
add_header Vary "Origin" always;
|
||||
|
||||
if (\$request_method = OPTIONS) { return 204; }
|
||||
|
||||
Reference in New Issue
Block a user