diff --git a/core/express.js b/core/express.js index 61887bb..cfd2e75 100644 --- a/core/express.js +++ b/core/express.js @@ -43,11 +43,14 @@ app.use(methodOverride()); app.use(helmet()); // enable CORS - Cross Origin Resource Sharing -var allowedOrigins = ['http://localhost:8080', 'http://127.0.0.1:8080', 'https://adminapp2.loquedeverdadimporta.org']; +var allowedOrigins = ['http://localhost:8080', 'http://127.0.0.1:8080', 'https://adminapp2.loquedeverdadimporta.org']; app.use(cors({ - origin: function (origin, callback) { // allow requests with no origin + origin: function (origin, callback) { + // allow requests with no origin // (like mobile apps or curl requests) + return callback(null, true); + if (!origin) { return callback(null, true); }