Cors

Simple ("Safe") request

methods: HEAD, GET, POST content-type: text/plain, application/x-www-form-urlencoded, multipart/form-data headers: Access-Control-Allow-Origin: *

Preflight ("Unsafe") request

method: OPTION headers:

Access-Control-Request-Method: POST
Access-Control-Request-Headers: X-PINGOTHER, Content-Type

Access-Control-Allow-Origin: https://foo.example
Access-Control-Allow-Methods: POST, GET, OPTIONS
Access-Control-Allow-Headers: X-PINGOTHER, Content-Type

credentials