Discussion on: Understanding CORS

Robert Linder

In the "Allowing multiple origins" example, Vary: Origin should be set in the response to avoid incorrect content being served (if content may differ depending on the requesting origin). See

Martin Splitt Author

Good point, thanks for your input! Added it to the example in that section :)