diff --git a/module/Rest/src/Middleware/CrossDomainMiddleware.php b/module/Rest/src/Middleware/CrossDomainMiddleware.php index 4327df9e..d6b84d5b 100644 --- a/module/Rest/src/Middleware/CrossDomainMiddleware.php +++ b/module/Rest/src/Middleware/CrossDomainMiddleware.php @@ -41,7 +41,8 @@ class CrossDomainMiddleware implements MiddlewareInterface } // Add Allow-Origin header - $response = $response->withHeader('Access-Control-Allow-Origin', $request->getHeader('Origin')); + $response = $response->withHeader('Access-Control-Allow-Origin', $request->getHeader('Origin')) + ->withHeader('Access-Control-Expose-Headers', 'Authorization'); if ($request->getMethod() !== 'OPTIONS') { return $response; }