]> git.openstreetmap.org Git - rails.git/blobdiff - public/oauth/crossdomain.xml
Use cancancan to authorize user_preference_controller
[rails.git] / public / oauth / crossdomain.xml
index 52e8397a3bdab1327607300b88157f32ed110976..a8029a905d5dc8ddb3797508f55ecf65257d788c 100644 (file)
@@ -2,9 +2,6 @@
 <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
 
 <cross-domain-policy>
-       <allow-access-from domain="*"/>
-       <allow-http-request-headers-from domain="*" headers="Authorization,X_HTTP_METHOD_OVERRIDE"/>
-       <allow-http-request-headers-from domain="*.openstreetmap.org" headers="*"/>
-       <allow-http-request-headers-from domain="*.openstreetmap.net" headers="*"/>
-       <allow-http-request-headers-from domain="*.openstreetmap.com" headers="*"/>
+       <allow-access-from domain="*" secure="false"/>
+       <allow-http-request-headers-from domain="*" headers="*" secure="false"/>
 </cross-domain-policy>