Return-Path: X-Original-To: apmail-airavata-dev-archive@www.apache.org Delivered-To: apmail-airavata-dev-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id BCAFE104C2 for ; Tue, 29 Oct 2013 14:21:54 +0000 (UTC) Received: (qmail 9260 invoked by uid 500); 29 Oct 2013 14:21:08 -0000 Delivered-To: apmail-airavata-dev-archive@airavata.apache.org Received: (qmail 9194 invoked by uid 500); 29 Oct 2013 14:21:06 -0000 Mailing-List: contact dev-help@airavata.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@airavata.apache.org Delivered-To: mailing list dev@airavata.apache.org Received: (qmail 8894 invoked by uid 99); 29 Oct 2013 14:20:47 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 29 Oct 2013 14:20:47 +0000 Date: Tue, 29 Oct 2013 14:20:47 +0000 (UTC) From: "Raminderjeet Singh (JIRA)" To: dev@airavata.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Closed] (AIRAVATA-870) Enable CORS support in Airavata server MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/AIRAVATA-870?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Raminderjeet Singh closed AIRAVATA-870. --------------------------------------- > Enable CORS support in Airavata server > -------------------------------------- > > Key: AIRAVATA-870 > URL: https://issues.apache.org/jira/browse/AIRAVATA-870 > Project: Airavata > Issue Type: Improvement > Reporter: Viknes Balasubramanee > Assignee: Chathuri Wimalasena > Fix For: 0.10 > > Attachments: Airavata-870-new.patch > > > With the GOAL of Airavata to have more support for REST APIs, Cross Domain requests become inevitable. Currently Airavata accepts requests from all domains for any operation which makes us open to attacks. The server should be able to handle such cross domain requests more effectively. We can add a CORS filter to handle this. -- This message was sent by Atlassian JIRA (v6.1#6144)