Ticket #20507: 20507.3.diff
File 20507.3.diff, 823 bytes (added by , 13 years ago) |
---|
-
wp-includes/class-wp-customize.php
71 71 if ( ! isset( $_REQUEST['customize'] ) || 'on' != $_REQUEST['customize'] ) 72 72 return; 73 73 74 $url = parse_url( admin_url() ); 75 $allowed_origins = array( 'http://' . $url[ 'host' ], 'https://' . $url[ 'host' ] ); 76 // @todo preserve port? 77 if ( isset( $_SERVER[ 'HTTP_ORIGIN' ] ) && in_array( $_SERVER[ 'HTTP_ORIGIN' ], $allowed_origins ) ) 78 $origin = $_SERVER[ 'HTTP_ORIGIN' ]; 79 else 80 $origin = $url[ 'scheme' ] . '://' . $url[ 'host' ]; 81 82 @header( 'Access-Control-Allow-Origin: ' . $origin ); 83 74 84 $this->start_previewing_theme(); 75 85 show_admin_bar( false ); 76 86 }