I found a temporary solution. I put a servlet filter in the end that just adds 
the Access-Control-Allow-Origin to the header.
Not an ideal solution from a security perspective. But something to unblock the 
client applications. We are any doing a overlay build of CAS. So, doing this 
was not hard.
-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to