Skip to content

Cannot Set CORS Headers Due to Improper Handling of requestOptions['headers'] #426

Description

@pedrodotvu

Summary

There is currently no way to set actual CORS headers (e.g., Access-Control-Allow-Origin) on objects, at least, using the SDK, due to two compounding issues in how headers are handled.


Problem

  1. Metadata-based headers are prefixed
    Using the metadata option when creating or updating objects results in all custom headers being prefixed, e.g.:
X-Object-Meta-Access-Control-Allow-Origin: *

This prevents these headers from functioning as proper CORS headers, which must be actual HTTP response headers (e.g., Access-Control-Allow-Origin).

  1. requestOptions['headers'] are ignored
    When attempting to pass headers via requestOptions, they are silently ignored due to this code pattern:
$options += $userValues['requestOptions'];

Since $options['headers'] is already set (even as an empty array) in the sendRequest method of the OperatorTrait, PHP's array union operator (+) causes user-supplied headers to be discarded — because the key already exists.


Suggested Fix

A minimal and backward-compatible fix we applied in our fork is the following:

if (array_key_exists('requestOptions', $userValues)) {
    $options += $userValues['requestOptions'];
}

if (array_key_exists('rawHttpHeaders', $userValues)) {
    $options['headers'] = array_merge(
        $options['headers'] ?? [],
        $userValues['rawHttpHeaders'] ?? []
    );
}

This preserves existing behavior with requestOptions, but allows users to pass explicit rawHttpHeaders for setting standard HTTP headers like:

'rawHttpHeaders' => [
    'Access-Control-Allow-Origin' => '*',
    'Access-Control-Allow-Methods' => 'GET, POST, OPTIONS',
]

Why This Matters

Without this change, the SDK is effectively unable to set real CORS headers, making it incompatible with workflows involving:

  • Browser-based file access
  • CDN configurations requiring CORS compliance
  • Any API integration that needs standard HTTP header control

Final Notes

Let me know if a patch would be helpful.

Thanks for your work on the SDK!

Best regards,
Pedro

Activity

  1. k0ka commented on May 30, 2025

    @k0ka
    Member

    Hello,

    thank you for the issue. I just fixed the headers key so it would be merged with options. It might make sense to replace += with some deep merge function, but I guess it should be good as is.

    Released in https://github.com/php-opencloud/openstack/releases/tag/v3.14.0

  2. pedrodotvu commented on May 30, 2025

    @pedrodotvu
    Author

    Hi k0ka,

    Thank you for the very quick turnover :) really appreciate it!

    Best regards,
    Pedro

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions