header('Access-Control-Allow-Origin', '*') ->header('Access-Control-Allow-credentials', true) ->header('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS'); if (!$request->isMethod('OPTIONS')) { return $response; } $allow = $response->headers->get('Allow'); // true list of allowed methods if (!$allow) { return $response; } $headers = [ 'Access-Control-Allow-Methods' => $allow, 'Access-Control-Max-Age' => 3600, 'Access-Control-Allow-Headers' => 'X-Requested-With, Origin, X-Csrftoken, Content-Type, Accept', ]; return $response->withHeaders($headers); } }