If not allowed, then the middleware will return a 400 on pre-flight
CORS requests.
Fixes #3129.
middleware = []
if config.get_bool('CORS_NOACCESSCONTROL'):
middleware = []
if config.get_bool('CORS_NOACCESSCONTROL'):
- middleware.append(Middleware(CORSMiddleware, allow_origins=['*']))
+ middleware.append(Middleware(CORSMiddleware,
+ allow_origins=['*'],
+ allow_methods=['GET', 'OPTIONS'],
+ max_age=86400))
log_file = config.LOG_FILE
if log_file:
log_file = config.LOG_FILE
if log_file: