Add the cors-csrf module
This commit is contained in:
25
cors-csrf/scripts/preflight.sh
Executable file
25
cors-csrf/scripts/preflight.sh
Executable file
@@ -0,0 +1,25 @@
|
||||
#!/usr/bin/env bash
|
||||
# Send one CORS preflight and print the status line and the headers that decide the outcome.
|
||||
#
|
||||
# ./scripts/preflight.sh https://spa.example.com POST /api/data
|
||||
#
|
||||
# A preflight is not a special kind of request. It is an OPTIONS carrying Origin and
|
||||
# Access-Control-Request-Method, and it is sent WITHOUT cookies or an Authorization header -
|
||||
# which is precisely why a chain that requires authentication rejects it.
|
||||
set -eu
|
||||
ORIGIN="${1:-https://spa.example.com}"
|
||||
METHOD="${2:-POST}"
|
||||
PATH_="${3:-/api/data}"
|
||||
|
||||
echo "\$ curl -s -i -X OPTIONS http://localhost:8080$PATH_ \\"
|
||||
echo " -H 'Origin: $ORIGIN' \\"
|
||||
echo " -H 'Access-Control-Request-Method: $METHOD' \\"
|
||||
echo " -H 'Access-Control-Request-Headers: content-type,x-xsrf-token'"
|
||||
echo
|
||||
curl -s -i -X OPTIONS "http://localhost:8080$PATH_" \
|
||||
-H "Origin: $ORIGIN" \
|
||||
-H "Access-Control-Request-Method: $METHOD" \
|
||||
-H "Access-Control-Request-Headers: content-type,x-xsrf-token" \
|
||||
| sed -n '1,/^\r$/p' \
|
||||
| grep -viE '^(date|keep-alive|connection|content-length|transfer-encoding):' \
|
||||
| sed 's/\r$//'
|
||||
Reference in New Issue
Block a user