fix: allow method for cors

This commit is contained in:
DarkSky
2026-01-05 13:14:56 +08:00
parent f5394b7450
commit f42246aba1

View File

@@ -179,7 +179,7 @@ function allowCors(
// Signed blob URLs redirect to *.usercontent.affine.pro without CORS headers.
setHeader(headers, 'Access-Control-Allow-Origin', origin);
setHeader(headers, 'Access-Control-Allow-Credentials', 'true');
setHeader(headers, 'Access-Control-Allow-Methods', 'GET, HEAD, OPTIONS');
setHeader(headers, 'Access-Control-Allow-Methods', 'GET, HEAD, PUT, OPTIONS');
setHeader(
headers,
'Access-Control-Allow-Headers',