Ability to set Access-Control-Allow-Headers
Organization Name (Required - If you are an Oracle Partner, please provide the organization you are logging the idea on behalf of):
KPMG
Description (Required):
Currently in a REST trigger we can only set Access-Control-Allow-Methods
and Access-Control-Allow-Origin
But there is no way to set Access-Control-Allow-Headers
This becomes an issue when a browser based app is calling OIC integration and that integration has custom headers.
So either default the custom headers configured in trigger to the Allowed Header or have a way to specify those in CORS settings.
.
Use Case and Business Need (Required):
Unable to call OIC Integration with custom headers from browser based applications
Tagged:
1