diff options
-rw-r--r-- | changelog.d/10114.misc | 1 | ||||
-rw-r--r-- | synapse/http/server.py | 2 |
2 files changed, 2 insertions, 1 deletions
diff --git a/changelog.d/10114.misc b/changelog.d/10114.misc new file mode 100644 index 0000000000..808548f7c7 --- /dev/null +++ b/changelog.d/10114.misc @@ -0,0 +1 @@ +Drop Origin and Accept from the value of the Access-Control-Allow-Headers response header. diff --git a/synapse/http/server.py b/synapse/http/server.py index 845651e606..efbc6d5b25 100644 --- a/synapse/http/server.py +++ b/synapse/http/server.py @@ -728,7 +728,7 @@ def set_cors_headers(request: Request): ) request.setHeader( b"Access-Control-Allow-Headers", - b"Origin, X-Requested-With, Content-Type, Accept, Authorization, Date", + b"X-Requested-With, Content-Type, Authorization, Date", ) |