mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-03 16:05:24 -04:00
Two cases produced a Warning for a request that needs no CORS headers at all, so the log filled with noise that pointed at nothing wrong. An empty Origin header satisfies isset(), so CORSHeaders() walked the servers list, matched nothing, and logged " is not found in servers list." with no value to print. Treat an empty Origin the same as no Origin. Browsers also send Origin on same-origin POST and fetch. Such a request needs no headers, but not finding the host in the Servers table still warned, so any install reached on a hostname the Servers table does not list warned on ordinary use. Log that at Debug instead. Genuine cross-origin requests still warn. Headers are unchanged; this only affects logging and the empty-Origin short circuit. The comparison ignores the scheme, so http:// against an https-served HTTP_HOST counts as same-origin - that only suppresses a log line, no header is emitted either way. Checked with a standalone assert script over same-origin with and without a port on both schemes, differing port, differing host, a suffix near-miss (hamburg.local vs hamburg) and a missing HTTP_HOST; only the first three go quiet.