diff --git a/src/Ui/UiRequest.py b/src/Ui/UiRequest.py index ffa0b6de..336a55f3 100644 --- a/src/Ui/UiRequest.py +++ b/src/Ui/UiRequest.py @@ -170,8 +170,6 @@ class UiRequest(object): headers.append(("Version", "HTTP/1.1")) headers.append(("Connection", "Keep-Alive")) headers.append(("Keep-Alive", "max=25, timeout=30")) - if content_type != "text/html": - headers.append(("Access-Control-Allow-Origin", "*")) # Allow json access on non-html files headers.append(("X-Frame-Options", "SAMEORIGIN")) # headers.append(("Content-Security-Policy", "default-src 'self' data: 'unsafe-inline' ws://127.0.0.1:* http://127.0.0.1:* wss://tracker.webtorrent.io; sandbox allow-same-origin allow-top-navigation allow-scripts")) # Only local connections if self.env["REQUEST_METHOD"] == "OPTIONS":