From 4f9136d2d55e1547c84fc394c0e5e1bb259d58d2 Mon Sep 17 00:00:00 2001
From: Akihiko Odaki <akihiko.odaki.4i@stu.hosei.ac.jp>
Date: Thu, 29 Mar 2018 03:40:18 +0900
Subject: [PATCH] Document CORS requirement for asset host (#6941)

---
 .env.production.sample | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/.env.production.sample b/.env.production.sample
index 1e5ed9f3d..9de2c0650 100644
--- a/.env.production.sample
+++ b/.env.production.sample
@@ -81,6 +81,10 @@ SMTP_FROM_ADDRESS=notifications@example.com
 # PAPERCLIP_ROOT_URL=/system
 
 # Optional asset host for multi-server setups
+# The asset host must allow cross origin request from WEB_DOMAIN or LOCAL_DOMAIN
+# if WEB_DOMAIN is not set. For example, the server may have the
+# following header field:
+# Access-Control-Allow-Origin: https://example.com/
 # CDN_HOST=https://assets.example.com
 
 # S3 (optional)
-- 
GitLab