Middleware: CorsMiddleware

The CorsMiddleware registered in app.php adds Access-Control-Allow-Origin + related headers to every response. It also intercepts OPTIONS preflight requests automatically — try curl -X OPTIONS http://host/anything.

Origin you sent

(none)

Response

Status
200 OK
Access-Control-Allow-Origin
* (or whatever ZEALPHP_CORS_ORIGINS is set to)
Vary
Origin