Commit fd91559b authored by Emiliano Balbuena's avatar Emiliano Balbuena

(fix): Origin's scheme should have more relevance for CORS

1 merge request!400SSO for Pro sites
Pipeline #97076605 passed with stages
in 7 minutes and 20 seconds
......@@ -59,8 +59,8 @@ class ProMiddleware implements RouterMiddleware
$serverParams = $request->getServerParams() ?? [];
$originalHost = $serverParams['HTTP_HOST'];
$scheme = $request->getUri()->getScheme();
$host = parse_url($serverParams['HTTP_ORIGIN'] ?? '', PHP_URL_HOST) ?: $originalHost;
$scheme = parse_url($serverParams['HTTP_ORIGIN'] ?? '', PHP_URL_SCHEME) ?: $request->getUri()->getScheme();
if (!$host) {
return null;
......
Please register or to comment