From: Gergő Tisza Date: Sun, 11 Jan 2015 07:55:40 +0000 (-0800) Subject: Add Timing-Allow-Origin header for cross-domain API responses X-Git-Tag: 1.31.0-rc.0~12685^2 X-Git-Url: http://git.cyclocoop.org/%7B%24admin_url%7Dcompta/comptes/journal.php?a=commitdiff_plain;h=26a2d54b4a1a9bdefbefccfddd2b74c43b9d7965;p=lhc%2Fweb%2Fwiklou.git Add Timing-Allow-Origin header for cross-domain API responses This makes it possible to get detailed network timing information via ResourceTiming. Change-Id: Ie88d4354285420014c0f1612446ba94fc2a8c68f --- diff --git a/includes/api/ApiMain.php b/includes/api/ApiMain.php index 82ed295696..9a980544ec 100644 --- a/includes/api/ApiMain.php +++ b/includes/api/ApiMain.php @@ -554,6 +554,7 @@ class ApiMain extends ApiBase { $response->header( "Access-Control-Allow-Origin: $originHeader" ); $response->header( 'Access-Control-Allow-Credentials: true' ); + $response->header( "Timing-Allow-Origin: $originHeader" ); # http://www.w3.org/TR/resource-timing/#timing-allow-origin if ( !$preflight ) { $response->header( 'Access-Control-Expose-Headers: MediaWiki-API-Error, Retry-After, X-Database-Lag' );