diff --git a/includes/APICore.php b/includes/APICore.php index daaf29c5..758170de 100644 --- a/includes/APICore.php +++ b/includes/APICore.php @@ -39,7 +39,7 @@ private function setAllowedOriginHeader() { header( 'Access-Control-Allow-Origin: *' ); } else if( $this->isAllowedOrigin() ) { - header( 'Access-Control-Allow-Origin: ' . ($_SERVER['HTTP_ORIGIN'] || '*') ); + header( 'Access-Control-Allow-Origin: ' . $this->RequestHeaders[ "Origin" ] ); } else { header( "Access-Control-Allow-Origin: {$_SERVER['HTTP_HOST']}" );