Jump to navigation Jump to search
This page is a translated version of the page Manual:$wgCrossSiteAJAXdomains and the translation is 32% complete.
Other languages:
English • ‎français • ‎magyar • ‎polski • ‎中文 • ‎日本語
API: $wgCrossSiteAJAXdomains
Domains that may make cross-site Ajax requests to the MediaWiki API.
導入されたバージョン:1.16.0 (r54127)


Allows Ajax requests from certain domains to make cross-site requests to a wiki's API (see Manual:CORS for example usage). これは Access-Control-Allow-Origin HTTP ヘッダーを使用します。 Note that some older browsers don't support this. This only affects requests to the API. Other entry points (index.php) are not affected.

The value must be a list of allowed domain names, which can include shell-style wildcards (? to match any character, * to match any number (including zero) of characters). An empty array means no external access is allowed.

Some examples:

Allow any domain to access the API via Ajax (This is insecure):

$wgCrossSiteAJAXdomains = [

Allow two specific domains:

$wgCrossSiteAJAXdomains = [

Allow all subdomains of a domain (including "deep" subdomains such as

$wgCrossSiteAJAXdomains = [

使用例は gerrit:9624 を参照してください。

警告 警告: Any site listed in this config setting can take actions on behalf of your logged in users if they visit that site. Only include sites that you trust in this variable