Files
zoneminder/web/includes
Isaac Connor d8f1a7d2d4 fix: stop CORSHeaders warning about empty and same-origin requests
Two cases produced a Warning for a request that needs no CORS headers at
all, so the log filled with noise that pointed at nothing wrong.

An empty Origin header satisfies isset(), so CORSHeaders() walked the
servers list, matched nothing, and logged " is not found in servers list."
with no value to print.  Treat an empty Origin the same as no Origin.

Browsers also send Origin on same-origin POST and fetch.  Such a request
needs no headers, but not finding the host in the Servers table still
warned, so any install reached on a hostname the Servers table does not
list warned on ordinary use.  Log that at Debug instead.  Genuine
cross-origin requests still warn.

Headers are unchanged; this only affects logging and the empty-Origin
short circuit.  The comparison ignores the scheme, so http:// against an
https-served HTTP_HOST counts as same-origin - that only suppresses a log
line, no header is emitted either way.

Checked with a standalone assert script over same-origin with and without
a port on both schemes, differing port, differing host, a suffix near-miss
(hamburg.local vs hamburg) and a missing HTTP_HOST; only the first three
go quiet.
2026-08-27 18:34:54 -04:00
..