Files
DL6ER ae3b850188 Send CORS headers on 204 and error responses
Cross-origin web apps could not use DELETE endpoints. Their 204 No Content
answer, like every error response, goes through
`my_send_http_error_headers()`, which did not call `send_cors_header()`, so
the browser discarded it for lack of `Access-Control-Allow-Origin`. The 200
responses sent via `mg_send_http_ok()` always carried it.

Preflights need no change in FTL: CivetWeb answers every request carrying
both `Origin` and `Access-Control-Request-Method` itself before it reaches
`api_handler()`. The tests cover both the preflight and the CORS header on a
non-200 response.

Closes #2261

Signed-off-by: DL6ER <dl6er@dl6er.de>
2026-09-17 06:34:51 +02:00
..