diff --git a/pwnagotchi/ui/web.py b/pwnagotchi/ui/web.py index 021c37a..82af269 100644 --- a/pwnagotchi/ui/web.py +++ b/pwnagotchi/ui/web.py @@ -138,7 +138,7 @@ class Handler(BaseHTTPRequestHandler): # check the Origin header vs CORS def _is_allowed(self): origin = self.headers.get('origin') - if not origin: + if not origin and Handler.AllowedOrigin != '*': logging.warning("request with no Origin header from %s" % self.address_string()) return False