[
https://issues.apache.org/jira/browse/SHIRO-725?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17070253#comment-17070253
]
Benjamin Marwell commented on SHIRO-725:
----------------------------------------
Sounds like a good idea to me. It perfectly suits into Apache Shiro, describing
itself as a security framework.
Some questions, but this list is not mean to be exhaustive:
* Is this a dedicated support module (e.g. like
{color:#0747a6}{{support/jaxrs}}{color} is)? Or is this going into the
{color:#0747a6}{{web}}{color} module?
* Does it read from {color:#0747a6}{{shiro.ini}}{color} as well? If so, new
section {color:#0747a6}{{[CORS]}}{color}?
* How would the syntax look like? I am thinking of a similar configuration
like the {color:#0747a6}{{[url]}}{color} section, because we might need to have
a different configuration per URL.
* Which statements need to be supported? Thinking of:
** Access-Control-Allow-Origin
** Access-Control-Allow-Methods
** Access-Control-Allow-Headers
** Access-Control-Allow-Credentials
** Access-Control-Expose-Headers
** Access-Control-Max-Age
* How to parse/react to request headers?
** Access-Control-Request-Method
** Access-Control-Request-Headers
Documentation on mozilla:
[https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#The_HTTP_response_headers]
> Add a CORS filter
> -----------------
>
> Key: SHIRO-725
> URL: https://issues.apache.org/jira/browse/SHIRO-725
> Project: Shiro
> Issue Type: Improvement
> Components: Web
> Reporter: Francois Papon
> Assignee: Francois Papon
> Priority: Major
> Fix For: 1.6.0
>
>
> It would be usefull to add a new filter in order to deal with CORS request.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)