Ludovic Courtès writes:

> Roel Janssen <> skribis:
>> Ludovic Courtès writes:
>>> Roel Janssen <> skribis:
>>>> Ludovic Courtès writes:
>>>>> Roel Janssen <> skribis:
>>> [...]
>>>>>> We might need to add a HTTP header from the GNU server to allow
>>>>>> loading data from external sources:
>>>>> Indeed, because here the requests get blocked.  Could you get in touch
>>>>> with and report back?
>>>> At last!  I received an e-mail today that the sysadmins made the change
>>>> to allow fetching data from  So now it should work once
>>>> it is uploaded to
>>> Good!  I applied the patch and deployed the new web page:
>>> However, it’s still failing:
>>>   17:00:49.802 Cross-Origin Request Blocked: The Same Origin Policy 
>>> disallows reading the remote resource at 
>>>  (Reason: CORS header 'Access-Control-Allow-Origin' missing).1 <unknown>
>>> Ideas?
>> Yes, I think it only works when the origin is  I
>> contacted the sysadmins again to figure this out.  Could you leave the
>> page there for a couple of days?  That way I can give them a live
>> example.
> Sure.
> But indeed, there’s no ‘Access-Control-Allow-Origin’ HTTP header
> returned for <>.

I've got a response, and it might be easier than I thought it would be.

We need to add the following line to the response header at

  Access-Control-Allow-Origin: "";

Here's how to do it:

Which boils down to adding this line to the nginx config:
  add_header 'Access-Control-Allow-Origin' '';

Kind regards,

Reply via email to