Revert r17851 and just give non-local flash clients access to
authorTom Hughes <tom@compton.nu>
Tue, 29 Sep 2009 16:24:07 +0000 (16:24 +0000)
committerTom Hughes <tom@compton.nu>
Tue, 29 Sep 2009 16:24:07 +0000 (16:24 +0000)
the X_HTTP_METHOD_OVERRIDE header.

public/api/crossdomain.xml
public/oauth/crossdomain.xml

index 669cae3..52e8397 100644 (file)
@@ -3,5 +3,8 @@
 
 <cross-domain-policy>
        <allow-access-from domain="*"/>
-       <allow-http-request-headers-from domain="*" headers="*"/>
+       <allow-http-request-headers-from domain="*" headers="Authorization,X_HTTP_METHOD_OVERRIDE"/>
+       <allow-http-request-headers-from domain="*.openstreetmap.org" headers="*"/>
+       <allow-http-request-headers-from domain="*.openstreetmap.net" headers="*"/>
+       <allow-http-request-headers-from domain="*.openstreetmap.com" headers="*"/>
 </cross-domain-policy>
index 669cae3..52e8397 100644 (file)
@@ -3,5 +3,8 @@
 
 <cross-domain-policy>
        <allow-access-from domain="*"/>
-       <allow-http-request-headers-from domain="*" headers="*"/>
+       <allow-http-request-headers-from domain="*" headers="Authorization,X_HTTP_METHOD_OVERRIDE"/>
+       <allow-http-request-headers-from domain="*.openstreetmap.org" headers="*"/>
+       <allow-http-request-headers-from domain="*.openstreetmap.net" headers="*"/>
+       <allow-http-request-headers-from domain="*.openstreetmap.com" headers="*"/>
 </cross-domain-policy>