<div dir="ltr">I noticed that you are not setting &quot;Access-Control-Allow-Credentials&quot;. I&#39;m not sure what the underlying JS is setting .withCredentials on the XMLHttpRequest object, but if it is then this request would fail.<div>
<br></div><div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On 19 June 2013 12:03, Matthias Wessendorf <span dir="ltr">&lt;<a href="mailto:matzew@apache.org" target="_blank">matzew@apache.org</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><br><div class="gmail_extra"><br><br><div class="gmail_quote"><div class="im">On Wed, Jun 19, 2013 at 11:59 AM, Bruno Oliveira <span dir="ltr">&lt;<a href="mailto:bruno@abstractj.org" target="_blank">bruno@abstractj.org</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Have you tried Resteasy mailing list?<br></blockquote><div><br></div></div><div>that&#39;s next :-) </div><div><br>
</div><div>I guess I wanted a second pair of eyes here :)  </div><div><div class="h5"><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div><br>
Matthias Wessendorf wrote:<br>
&gt; Hi,<br>
&gt;<br>
&gt; trying to add CORS, to the Server (using RestEasy), I did this:<br>
&gt; <a href="https://github.com/aerogear/aerogear-unified-push-server/commit/7ccb2e7fb" target="_blank">https://github.com/aerogear/aerogear-unified-push-server/commit/7ccb2e7fb</a><br>
&gt;<br>
&gt; (and some more variations.... (e.g. see the comment out<br>
&gt; &quot;Access-Control-Allow-Origin&quot;, where I am returing the EXACT Origin))<br>
&gt;<br>
&gt;<br>
&gt; Here is a JavaScript sample:<br>
&gt; <a href="http://jsfiddle.net/JY6n4/" target="_blank">http://jsfiddle.net/JY6n4/</a><br>
&gt;<br>
&gt;<br>
&gt; Just click on the &quot;Register a device&quot; button, and see the errors in the<br>
&gt; console....<br>
&gt;<br>
&gt; So, I am always (with the above jsFiddle) getting:<br>
</div>&gt; Origin <a href="http://fiddle.jshell.net" target="_blank">http://fiddle.jshell.net</a> &lt;<a href="http://fiddle.jshell.net/" target="_blank">http://fiddle.jshell.net/</a>&gt; is not<br>
<div>&gt; allowed by Access-Control-Allow-Origin.<br>
&gt;<br>
&gt; regardless if I use &quot;*&quot; or &quot;<a href="http://fiddle.jshell.net" target="_blank">http://fiddle.jshell.net</a>&quot; (explicit Origin),<br>
&gt; on the &quot;Access-Control-Allow-Origin&quot;.     I always thought that &quot;*&quot; is a<br>
&gt; wildcard.... allowing everybody and their mother to access the server.<br>
&gt;<br>
&gt; BTW.<br>
&gt; This happens with jQuery _and_ vanilla.js (XHR)..... So....... I am<br>
&gt; really overasked, but ... is it possible that the response is correct<br>
&gt; (at least the setup / my src), but that RestEasy has any problems with<br>
&gt; that stuff ??<br>
&gt;<br>
&gt;<br>
&gt; A few more eyes are highly appreciated on this &quot;issue&quot;.<br>
&gt;<br>
&gt; thanks!!<br>
&gt; Matthias<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; Matthias Wessendorf<br>
&gt;<br>
&gt; blog: <a href="http://matthiaswessendorf.wordpress.com/" target="_blank">http://matthiaswessendorf.wordpress.com/</a><br>
&gt; sessions: <a href="http://www.slideshare.net/mwessendorf" target="_blank">http://www.slideshare.net/mwessendorf</a><br>
&gt; twitter: <a href="http://twitter.com/mwessendorf" target="_blank">http://twitter.com/mwessendorf</a><br>
&gt;<br>
</div>&gt; _______________________________________________<br>
&gt; aerogear-dev mailing list<br>
&gt; <a href="mailto:aerogear-dev@lists.jboss.org" target="_blank">aerogear-dev@lists.jboss.org</a><br>
&gt; <a href="https://lists.jboss.org/mailman/listinfo/aerogear-dev" target="_blank">https://lists.jboss.org/mailman/listinfo/aerogear-dev</a><br>
<span><font color="#888888"><br>
--<br>
abstractj<br>
<br>
_______________________________________________<br>
aerogear-dev mailing list<br>
<a href="mailto:aerogear-dev@lists.jboss.org" target="_blank">aerogear-dev@lists.jboss.org</a><br>
<a href="https://lists.jboss.org/mailman/listinfo/aerogear-dev" target="_blank">https://lists.jboss.org/mailman/listinfo/aerogear-dev</a><br>
</font></span></blockquote></div></div></div><div><div class="h5"><br><br clear="all"><div><br></div>-- <br>Matthias Wessendorf <br><br>blog: <a href="http://matthiaswessendorf.wordpress.com/" target="_blank">http://matthiaswessendorf.wordpress.com/</a><br>

sessions: <a href="http://www.slideshare.net/mwessendorf" target="_blank">http://www.slideshare.net/mwessendorf</a><br>twitter: <a href="http://twitter.com/mwessendorf" target="_blank">http://twitter.com/mwessendorf</a>
</div></div></div></div>
<br>_______________________________________________<br>
aerogear-dev mailing list<br>
<a href="mailto:aerogear-dev@lists.jboss.org">aerogear-dev@lists.jboss.org</a><br>
<a href="https://lists.jboss.org/mailman/listinfo/aerogear-dev" target="_blank">https://lists.jboss.org/mailman/listinfo/aerogear-dev</a><br></blockquote></div><br></div>