In the HTTP CORS spec, what’s the difference between Allow-Headers and Expose-Headers?

Access-Control-Allow-Headers

Used in response to a preflight request to indicate which HTTP headers can be used when making the actual request.

Access-Control-Expose-Headers

This header lets a server whitelist headers that browsers are allowed to access. For example:

Source:
https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS

Leave a Comment

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)