Hacker News new | ask | show | jobs
by wefarrell 2321 days ago
Access-Control-Allow-Credentials too and it needs to be configured on both the client and the server.
1 comments

If the API is not yours, why not set up a proxy on your domain (where you can change the origin header)? Envoy, nginx, etc.