only allow cors on api routes

This commit is contained in:
Devin Howard 2016-04-06 20:09:25 +08:00
parent 7de642ccb2
commit e27d64e643

View file

@ -1,7 +1,7 @@
Rails.application.config.middleware.insert_before 0, Rack::Cors do
allow do
origins '*'
resource '*',
resource '/api/*',
headers: :any,
methods: [:get, :post, :put, :delete, :options, :head]
end