Fixes from frontend/backend url separation (#1829)

* Fixes from frontend/backend url separation

This fixes the CORS and CSP headers.

Also, in thie commit, I removed the cors_supports_credentials config parameter,
which was recently introduced.
Instead, the logic determines the need to use CORS headers if the
web_page_url is set.

 #1778
This commit is contained in:
bmccandless
2020-09-12 10:56:31 -07:00
committed by GitHub
parent 4b240920e2
commit 6a7ae8bc8e
5 changed files with 24 additions and 14 deletions
-5
View File
@@ -14,11 +14,6 @@ server:
server_timing_headers: false
csp_directives: null
# CORS: Cross Origin Resource Sharing. If true, this allow users to make
# authenticated requests. This allows cookies and credentials to be submitted
# across domains
cors_supports_credentials: false
# By default, cellxgene will serve api requests from the same base url as the webpage.
# In general api_base_url and web_base_url will not need to be set.
# There are two reasons to set these parameters: