| Index: Source/core/fetch/CrossOriginAccessControl.cpp
|
| diff --git a/Source/core/fetch/CrossOriginAccessControl.cpp b/Source/core/fetch/CrossOriginAccessControl.cpp
|
| index b9433ac057ac9715de2dbba777664ea0ecd75d38..90c032352de04f55b34a5a3705dbaa815f5275d4 100644
|
| --- a/Source/core/fetch/CrossOriginAccessControl.cpp
|
| +++ b/Source/core/fetch/CrossOriginAccessControl.cpp
|
| @@ -141,7 +141,7 @@ bool passesAccessControlCheck(const ResourceResponse& response, StoredCredential
|
|
|
| // A wildcard Access-Control-Allow-Origin can not be used if credentials are to be sent,
|
| // even with Access-Control-Allow-Credentials set to true.
|
| - const String& accessControlOriginString = response.httpHeaderField(accessControlAllowOrigin);
|
| + const AtomicString& accessControlOriginString = response.httpHeaderField(accessControlAllowOrigin);
|
| if (accessControlOriginString == "*" && includeCredentials == DoNotAllowStoredCredentials)
|
| return true;
|
|
|
| @@ -162,7 +162,7 @@ bool passesAccessControlCheck(const ResourceResponse& response, StoredCredential
|
| }
|
|
|
| if (includeCredentials == AllowStoredCredentials) {
|
| - const String& accessControlCredentialsString = response.httpHeaderField(accessControlAllowCredentials);
|
| + const AtomicString& accessControlCredentialsString = response.httpHeaderField(accessControlAllowCredentials);
|
| if (accessControlCredentialsString != "true") {
|
| errorDescription = "Credentials flag is 'true', but the 'Access-Control-Allow-Credentials' header is '" + accessControlCredentialsString + "'. It must be 'true' to allow credentials.";
|
| return false;
|
|
|