# -*- coding: utf-8 -*- import json from django import http COORS_ALLOWED_ORIGINS = '*' COORS_ALLOWED_METHODS = ['POST', 'GET', 'OPTIONS', 'PUT', 'DELETE', 'PATCH', 'HEAD'] COORS_ALLOWED_HEADERS = ['content-type', 'x-requested-with', 'authorization', 'accept-encoding', 'x-disable-pagination', 'x-host'] COORS_ALLOWED_CREDENTIALS = True COORS_EXPOSE_HEADERS = ["x-pagination-count", "x-paginated", "x-paginated-by", "x-paginated-by", "x-pagination-current", "x-site-host", "x-site-register"] class CoorsMiddleware(object): def _populate_response(self, response): response["Access-Control-Allow-Origin"] = COORS_ALLOWED_ORIGINS response["Access-Control-Allow-Methods"] = ",".join(COORS_ALLOWED_METHODS) response["Access-Control-Allow-Headers"] = ",".join(COORS_ALLOWED_HEADERS) response["Access-Control-Expose-Headers"] = ",".join(COORS_EXPOSE_HEADERS) if COORS_ALLOWED_CREDENTIALS: response["Access-Control-Allow-Credentials"] = 'true' def process_request(self, request): if 'HTTP_ACCESS_CONTROL_REQUEST_METHOD' in request.META: response = http.HttpResponse() self._populate_response(response) return response return None def process_response(self, request, response): self._populate_response(response) return response