Slide 31
Slide 31 text
XSS_ORIGINS = 'http://localhost.com:3501'
XSS_METHODS = ['POST', 'GET', 'OPTIONS', 'PUT', 'DELETE']
XSS_HEADERS = ['Content-Type', 'x-requested-with', '*']
XSS_CREDENTIALS = 'true'
class XSSharing(object):
def process_response(self, request, response):
response['Access-Control-Allow-Origin'] = XSS_ORIGINS
response['Access-Control-Allow-Methods'] \
= ",".join(XSS_METHODS)
response['Access-Control-Allow-Headers'] \
= ",".join(XSS_HEADERS)
response['Access-Control-Allow-Credentials'] \
= XSS_CREDENTIALS
return response
https://gist.github.com/426829