@@ -38,7 +38,7 @@ class EnableCrossRequestMiddleware
];
if (empty($allow_origin) || in_array($origin, $allow_origin)) {
//允许所有资源跨域
- $response->header('Access-Control-Allow-Origin', empty($allow_origin)? '*' : $origin);
+ $response->header('Access-Control-Allow-Origin', $origin);
// 允许通过的响应报头
$response->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Cookie, X-CSRF-TOKEN, Accept, Authorization, X-XSRF-TOKEN');
// 允许axios获取响应头中的Authorization