2 * ============LICENSE_START=======================================================
3 * Copyright (C) 2016-2018 Ericsson. All rights reserved.
4 * ================================================================================
5 * Licensed under the Apache License, Version 2.0 (the "License");
6 * you may not use this file except in compliance with the License.
7 * You may obtain a copy of the License at
9 * http://www.apache.org/licenses/LICENSE-2.0
11 * Unless required by applicable law or agreed to in writing, software
12 * distributed under the License is distributed on an "AS IS" BASIS,
13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 * See the License for the specific language governing permissions and
15 * limitations under the License.
17 * SPDX-License-Identifier: Apache-2.0
18 * ============LICENSE_END=========================================================
21 package org.onap.policy.apex.plugins.event.carrier.restserver;
23 import java.io.IOException;
25 import javax.ws.rs.container.ContainerRequestContext;
26 import javax.ws.rs.container.ContainerResponseContext;
27 import javax.ws.rs.container.ContainerResponseFilter;
28 import javax.ws.rs.ext.Provider;
31 * This class implements ContainerResponseFilter which intercepts every request/response coming to REST server and adds
32 * the required HTTP headers to support CORS.
34 * @author Ram Krishna Verma (ram.krishna.verma@ericsson.com)
37 public class AccessControlFilter implements ContainerResponseFilter {
40 public void filter(final ContainerRequestContext requestContext, final ContainerResponseContext responseContext)
42 responseContext.getHeaders().add("Access-Control-Allow-Origin", requestContext.getHeaderString("Origin"));
44 responseContext.getHeaders().add("Access-Control-Expose-Headers", "Content-Type, Accept, Allow");
46 responseContext.getHeaders().add("Access-Control-Allow-Headers", "Origin, Content-Type, Accept");
48 responseContext.getHeaders().add("Access-Control-Allow-Credentials", "true");
50 responseContext.getHeaders().add("Access-Control-Allow-Methods", "OPTIONS, GET, POST, PUT");