Uploaded image for project: 'Hippo CMS'
  1. Hippo CMS
  2. CMS-13152

Configure SaaS setup to by default not allow credentials for Page Model API requests

    XMLWordPrintable

Details

    • Task
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • None
    • None
    • None
    • None
    • 0.25
    • Quasar
    • Puma Sprint 232, Puma Sprint 233, Puma Sprint 234

    Description

      For version 14.x, a lot of customers use the url rewriter or some proxy to support an SPA. However, in case of the 'token based authorization', we do not need a proxy, and it should not even be needed to send credentials with a request from the SPA to BrX.

      Therefor in the SaaS version, since we there do not use the proxy solution ever but only the token based access, we should not by default support credentials for CORS requests.

      We should however keep the option to support it (later) : Depending on how the commerce (or other) integration(s) will be, it might be that we need by default the 'allow credentials' again for CORS requests

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              aschrijvers Ard Schrijvers
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: