Hey Eric / Marc,
Everything going good so far with the CORS fix but guessing there is something still, or maybe i'm doing something wrong ( it always happened to me ).
I have setup my CORS Policy in API Man and included "Access-Control-Allow-Methods" : "OPTIONS","GET","POST","DELETE",'PUT".
But i get a 403 and "CORS: Invalid preflight request; must use OPTIONS verb." on ANY service that is not GET.
OPTIONS Header :
Remote Address:
Request URL:
Request Method:
OPTIONS
Status Code:
200 OK
- Response Headersview source
Access-Control-Allow-Headers:
Accept, Authorization, Head
Access-Control-Allow-Methods:
OPTIONS, GET, POST, DELETE, PUT
Access-Control-Allow-Origin:
Access-Control-Max-Age:
0
Connection:
keep-alive
Date:
Thu, 27 Aug 2015 18:44:39 GMT
Server:
WildFly/8
Transfer-Encoding:
chunked
X-Powered-By:
Undertow/1
- Request Headersview source
Accept:
*/*
Accept-Encoding:
gzip, deflate, sdch
Accept-Language:
en-US,en;q=0.8,ar;q=0.6
Access-Control-Request-Headers:
accept, authorization
Access-Control-Request-Method:
POST
Cache-Control:
no-cache
Connection:
keep-alive
Host:
dev-internal-api.expdev.local
Origin:
Pragma:
no-cache
Referer:
POST HEADER
Remote Address:
Request URL:
Request Method:
POST
Status Code:
403 Forbidden
- Response Headersview source
Access-Control-Allow-Origin:
Connection:
keep-alive
Content-Length:
195
Content-Type:
application/json
Date:
Thu, 27 Aug 2015 18:44:39 GMT
Server:
WildFly/8
X-Policy-Failure-Code:
400
X-Policy-Failure-Message:
CORS: Invalid preflight request; must use OPTIONS verb.
X-Policy-Failure-Type:
Authorization
X-Powered-By:
Undertow/1
- Request Headersview source
Accept:
application/json, text/plain, */*
Accept-Encoding:
gzip, deflate
Accept-Language:
en-US,en;q=0.8,ar;q=0.6
Authorization:
Bearer eyJhbGciOiJSUzI1NiJ9.eyJqdGkiOiJkYTI.................................qoQRgKQ
Cache-Control:
no-cache
Connection:
keep-alive
Content-Length:
0
Host:
dev-internal-api.expdev.local
Origin:
Pragma:
no-cache