diff --git a/CORS.md b/CORS.md index 0f2234d..7a39535 100644 --- a/CORS.md +++ b/CORS.md @@ -71,4 +71,19 @@ curl -I -X OPTIONS -H "Origin: https://echo-reality.com" \ "https://feed.falsefinish.club/Echo%20Reality/PINK%20FLIGHT/MP3%20BOUNCE/01.%20PINK%20FLIGHT%20ATTENDANT.mp3" ``` -The response should include the `Access-Control-Allow-Origin: https://echo-reality.com` header. \ No newline at end of file +The response should include the `Access-Control-Allow-Origin: https://echo-reality.com` header. + +### Quick test `.htaccess` for DreamHost + +```apache +# TEMPORARY - Allow all origins for testing + + + Header set Access-Control-Allow-Origin "*" + Header set Access-Control-Allow-Methods "GET, HEAD, OPTIONS" + Header set Access-Control-Expose-Headers "ETag, Last-Modified, Content-Length" + + +``` + +This limits the wildcard CORS to just media files, which is a reasonable middle ground—your audio files are publicly accessible but you're not opening up everything on the domain. \ No newline at end of file