# Sets CORS headers for request from example1.com and example2.com pages # for both SSL and non-SSL SetEnvIf Origin "^https?://[^/]*(example1|example2)\.com$" ORIGIN=$0 Header set Access-Control-Allow-Origin %{ORIGIN}e env=ORIGIN Header set Access-Control-Allow-Credentials "true" env=ORIGIN # Always set Vary: Origin when it's possible you may send CORS headers Header merge Vary Origin