server('HTTP_ORIGIN') ?: ''; $allow_origin = [ 'https://www.xingyousoft.com', // 'https://audio.xingyousoft.com', // 'https://backup.xingyousoft.com', // 'https://batch_create.xingyousoft.com', // 'https://cad.xingyousoft.com', // 'https://compress.xingyousoft.com', // 'https://enlarge.xingyousoft.com', // 'https://extract.xingyousoft.com', // 'https://jimp.xingyousoft.com', // 'https://ocr.xingyousoft.com', // 'https://pdf.xingyousoft.com', // 'https://rename.xingyousoft.com', // 'https://video.xingyousoft.com', // 'https://videos.xingyousoft.com', // 'https://watermark.xingyousoft.com', ]; if (in_array($origin, $allow_origin)) { $response->header('Access-Control-Allow-Origin', $origin); $response->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Cookie, X-CSRF-TOKEN, Accept, Authorization, X-XSRF-TOKEN'); $response->header('Access-Control-Expose-Headers', 'Authorization, authenticated'); $response->header('Access-Control-Allow-Methods', 'GET, POST, PATCH, PUT, OPTIONS'); $response->header('Access-Control-Allow-Credentials', 'true'); } return $response; } }