<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">Great!  Let us know the outcome.....<br>
      <br>
      Micah<br>
      <br>
      On 6/21/2013 11:35 AM, Tim Haverland - NOAA Federal wrote:<br>
    </div>
    <blockquote
cite="mid:CA+PWDsCgGxSc94mLo9+Syy9VAp_arKojY9aWgv-UWCn-n0qvWQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">Thanks Chi - standing by to test as soon as you can
        implement this.
        <div><br>
        </div>
        <div>Tim</div>
      </div>
      <div class="gmail_extra"><br>
        <br>
        <div class="gmail_quote">On Fri, Jun 21, 2013 at 11:25 AM, Chi
          Kang - NOAA Federal <span dir="ltr"><<a
              moz-do-not-send="true" href="mailto:chi.y.kang@noaa.gov"
              target="_blank">chi.y.kang@noaa.gov</a>></span> wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">Yea, i'm
            reading the same thing here. For the sake of argument /<br>
            testing let me try "*" and have Tim validate this.<br>
            <div class="HOEnZb">
              <div class="h5"><br>
                <br>
                On Thu, Jun 20, 2013 at 8:36 AM, Micah Wengren <<a
                  moz-do-not-send="true"
                  href="mailto:micah.wengren@noaa.gov">micah.wengren@noaa.gov</a>>
                wrote:<br>
                > I think it may involve a more complicated way to
                allow by TLD or .<a moz-do-not-send="true"
                  href="http://noaa.gov" target="_blank">noaa.gov</a>.<br>
                > Like you said yesterday Chi *.<a
                  moz-do-not-send="true" href="http://noaa.gov"
                  target="_blank">noaa.gov</a> might be a valid value
                for that<br>
                > header.  The server might need to dynamically read
                the Origin header from<br>
                > the request and return the same URL if it matches a
                rule.  See:<br>
                ><br>
                > <a moz-do-not-send="true"
href="http://www.cameronstokes.com/2010/12/26/cross-origin-resource-sharing-and-apache-httpd/"
                  target="_blank">http://www.cameronstokes.com/2010/12/26/cross-origin-resource-sharing-and-apache-httpd/</a><br>
                > or<br>
                > <a moz-do-not-send="true"
href="http://stackoverflow.com/questions/1653308/access-control-allow-origin-multiple-origin-domains"
                  target="_blank">http://stackoverflow.com/questions/1653308/access-control-allow-origin-multiple-origin-domains</a><br>
                ><br>
                > Might be more complicated than we expected to allow
                a specific domain<br>
                > instead of "*".<br>
                ><br>
                > Micah<br>
                ><br>
                ><br>
                ><br>
                > On 6/19/2013 4:25 PM, Tim Haverland - NOAA Federal
                wrote:<br>
                ><br>
                > Chi - if <a moz-do-not-send="true"
                  href="http://services.ogc.noaa.gov" target="_blank">services.ogc.noaa.gov</a>
                does not allow the header x-requested-with,<br>
                > and openlayers is sending that header, wouldn't
                that be a likely source of a<br>
                > problem?<br>
                ><br>
                > I agree that the error message points to an Origin
                issue, not headers, but<br>
                > it's possible that the error reported by chrome is
                not that helpful in<br>
                > pinpointing the actual problem.<br>
                ><br>
                > Regarding the Origin, my request is coming from a <a
                  moz-do-not-send="true" href="http://noaa.gov"
                  target="_blank">noaa.gov</a> server, so I<br>
                > can't think of any other reason why my request is
                being rejected on an<br>
                > Origin basis. You are accepting *.<a
                  moz-do-not-send="true" href="http://noaa.gov"
                  target="_blank">noaa.gov</a> so I'd think it would be<br>
                > accepted.<br>
                ><br>
                > Tim<br>
                ><br>
                ><br>
                ><br>
                > On Wed, Jun 19, 2013 at 3:01 PM, Micah Wengren <<a
                  moz-do-not-send="true"
                  href="mailto:micah.wengren@noaa.gov">micah.wengren@noaa.gov</a>><br>
                > wrote:<br>
                >><br>
                >> Chi,  I think it's the best option we have from
                a troubleshooting<br>
                >> perspective.  Other than that, I don't really
                have an answer myself, this<br>
                >> particular topic isn't an area I'm especially
                familiar with.  It would be<br>
                >> nice to see what is required in order to
                support this type of communication<br>
                >> with <a moz-do-not-send="true"
                  href="http://services.ogc.noaa.gov" target="_blank">services.ogc.noaa.gov</a>
                from NOAA users who want to deploy simple web<br>
                >> pages connecting to the services.  Tim's use
                case is a good model for what<br>
                >> other users might want.<br>
                >><br>
                >> Any suggestions welcome for what else to test
                though.  It might be that we<br>
                >> need to tell users that their
                Access-Control-Request-Headers needs to not<br>
                >> contain any custom header names in order for
                CORS to work (if this was<br>
                >> indeed the cause for the failure message).<br>
                >><br>
                >> Micah<br>
                >><br>
                >><br>
                >> On 6/19/2013 2:20 PM, Chi Kang - NOAA Federal
                wrote:<br>
                >>><br>
                >>> Explain to me why you think allowing
                Access-Control-Request-Headers:<br>
                >>> x-requested-with would solve this problem?<br>
                >>><br>
                >>><br>
                >>> On Tue, Jun 18, 2013 at 5:33 PM, Tim
                Haverland - NOAA Federal<br>
                >>> <<a moz-do-not-send="true"
                  href="mailto:tim.haverland@noaa.gov">tim.haverland@noaa.gov</a>>
                wrote:<br>
                >>>><br>
                >>>> OK, I was able to publish my page to
                our test server, and there's no<br>
                >>>> port<br>
                >>>> appended to the origin:<br>
                >>>><br>
                >>>> Accept:<br>
                >>>> */*<br>
                >>>> Accept-Encoding:<br>
                >>>> gzip,deflate,sdch<br>
                >>>> Accept-Language:<br>
                >>>> en-US,en;q=0.8<br>
                >>>> Access-Control-Request-Headers:<br>
                >>>> origin, x-requested-with<br>
                >>>> Access-Control-Request-Method:<br>
                >>>> GET<br>
                >>>> Cache-Control:<br>
                >>>> no-cache<br>
                >>>> Connection:<br>
                >>>> keep-alive<br>
                >>>> Host:<br>
                >>>> <a moz-do-not-send="true"
                  href="http://services.ogc.noaa.gov" target="_blank">services.ogc.noaa.gov</a><br>
                >>>> Origin:<br>
                >>>> <a moz-do-not-send="true"
                  href="http://www.st-test.nmfs.noaa.gov"
                  target="_blank">http://www.st-test.nmfs.noaa.gov</a><br>
                >>>> Pragma:<br>
                >>>> no-cache<br>
                >>>> Referer:<br>
                >>>> <a moz-do-not-send="true"
                  href="http://www.st-test.nmfs.noaa.gov/appstech/map-test"
                  target="_blank">http://www.st-test.nmfs.noaa.gov/appstech/map-test</a><br>
                >>>> User-Agent:<br>
                >>>> Mozilla/5.0 (Windows NT 6.1; WOW64)
                AppleWebKit/537.36 (KHTML, like<br>
                >>>> Gecko)<br>
                >>>> Chrome/27.0.1453.110 Safari/537.36<br>
                >>>><br>
                >>>><br>
                >>>> Still get the error:<br>
                >>>><br>
                >>>> Origin <a moz-do-not-send="true"
                  href="http://www.st-test.nmfs.noaa.gov"
                  target="_blank">http://www.st-test.nmfs.noaa.gov</a>
                is not allowed by<br>
                >>>> Access-Control-Allow-Origin<br>
                >>>><br>
                >>>> WOC, can you allow the header
                x-requested-with to see if that fixes the<br>
                >>>> problem?<br>
                >>>><br>
                >>>> Tim<br>
                >>>><br>
                >>>><br>
                >>>> On Tue, Jun 18, 2013 at 4:26 PM, Micah
                Wengren <<a moz-do-not-send="true"
                  href="mailto:micah.wengren@noaa.gov">micah.wengren@noaa.gov</a>><br>
                >>>> wrote:<br>
                >>>>><br>
                >>>>> Tim,<br>
                >>>>><br>
                >>>>> I found this:<br>
                >>>>><br>
                >>>>> <a moz-do-not-send="true"
href="http://www.html5rocks.com/en/tutorials/cors/#toc-handling-a-not-so-simple-request"
                  target="_blank">http://www.html5rocks.com/en/tutorials/cors/#toc-handling-a-not-so-simple-request</a><br>
                >>>>><br>
                >>>>> It sounds like jQuery or some part
                of the CMS is trying to ask whether<br>
                >>>>> the<br>
                >>>>> server will accept a header
                'x-requested-with'.  I'm sure that's not<br>
                >>>>> required for OpenLayers, but it's
                being inserted anyway by some part of<br>
                >>>>> your<br>
                >>>>> site code.  I don't know if that
                would cause the disallowed origin<br>
                >>>>> error<br>
                >>>>> message you're seeing if the
                non-standard header isn't supported or<br>
                >>>>> not, but<br>
                >>>>> if it is, there must be some way to
                disable that within the<br>
                >>>>> application, or<br>
                >>>>> this might get kinda complicated to
                get working.<br>
                >>>>><br>
                >>>>> Either way, are you sure that the
                port on your server isn't the issue?<br>
                >>>>>  From doing a little reading, it
                seems that since you're using a<br>
                >>>>> non-standard<br>
                >>>>> port, the 'Origin' header your site
                will be submitting should look like<br>
                >>>>> this:<br>
                >>>>><br>
                >>>>> Origin: <a moz-do-not-send="true"
                  href="http://triggerfish2.nmfs.noaa.gov:9992"
                  target="_blank">http://triggerfish2.nmfs.noaa.gov:9992</a><br>
                >>>>><br>
                >>>>> It's possible that that might not
                match the rules in our<br>
                >>>>> 'Access-Control-Allow-Origin'
                setting, if it's only a plain string<br>
                >>>>> comparison or something that Apache
                does.<br>
                >>>>><br>
                >>>>> Micah<br>
                >>>>><br>
                >>>>><br>
                >>>>><br>
                >>>>> On 6/18/2013 2:41 PM, Tim Haverland
                - NOAA Federal wrote:<br>
                >>>>><br>
                >>>>> I don't know the inner workings of
                our content management system, so<br>
                >>>>> not<br>
                >>>>> sure what's sending the
                x-requested-with header; however, I read that<br>
                >>>>> this<br>
                >>>>> is pretty common with Ajax
                requests, especially from jQuery.<br>
                >>>>><br>
                >>>>><br>
                >>>>> On Tue, Jun 18, 2013 at 2:22 PM,
                Micah Wengren <<a moz-do-not-send="true"
                  href="mailto:micah.wengren@noaa.gov">micah.wengren@noaa.gov</a>><br>
                >>>>> wrote:<br>
                >>>>>><br>
                >>>>>> Hi <a moz-do-not-send="true"
                  href="mailto:open.ogc@list.woc.noaa.gov">open.ogc@list.woc.noaa.gov</a>,<br>
                >>>>>><br>
                >>>>>> I'm sending this thread I've
                been on with Tim back to the email list<br>
                >>>>>> to<br>
                >>>>>> see if we can expedite
                troubleshooting what the issue is with a CORS<br>
                >>>>>> request<br>
                >>>>>> from Tim's development server
                to <a moz-do-not-send="true"
                  href="http://services.ogc.noaa.gov" target="_blank">services.ogc.noaa.gov</a>.
                He's<br>
                >>>>>> connecting<br>
                >>>>>> from:<br>
                >>>>>><br>
                >>>>>> <a moz-do-not-send="true"
                  href="http://triggerfish2.nmfs.noaa.gov:9992"
                  target="_blank">http://triggerfish2.nmfs.noaa.gov:9992</a><br>
                >>>>>><br>
                >>>>>> and trying to display one of
                our services on an OpenLayers map (and do<br>
                >>>>>> a<br>
                >>>>>> GetFeatureInfo request, which
                leads to the need  for CORS support).<br>
                >>>>>><br>
                >>>>>><br>
                >>>>>> I don't really have the answer
                to his question, anyone at the WOC know<br>
                >>>>>> about accepting non-standard
                headers?<br>
                >>>>>><br>
                >>>>>> Tim, do you know why this
                header is required from your side, and what<br>
                >>>>>> the<br>
                >>>>>> server should be doing with it?<br>
                >>>>>><br>
                >>>>>> Thanks,<br>
                >>>>>> Micah<br>
                >>>>>><br>
                >>>>>> On 6/18/2013 2:05 PM, Tim
                Haverland - NOAA Federal wrote:<br>
                >>>>>><br>
                >>>>>> Yeah, doesn't look like the
                port is an issue, however, my request is<br>
                >>>>>> sent<br>
                >>>>>> with these headers:<br>
                >>>>>><br>
                >>>>>> Access-Control-Request-Headers:<br>
                >>>>>> origin, x-requested-with<br>
                >>>>>><br>
                >>>>>><br>
                >>>>>> I've read that the server may
                need to accept "non-standard" headers.<br>
                >>>>>> x-requested-with is a
                non-standard header. Is this accepted on the<br>
                >>>>>> server<br>
                >>>>>> side?<br>
                >>>>>><br>
                >>>>>> Tim<br>
                >>>>>><br>
                >>>>>><br>
                >>>>>> On Tue, Jun 18, 2013 at 1:35
                PM, Tim Haverland - NOAA Federal<br>
                >>>>>> <<a moz-do-not-send="true"
                  href="mailto:tim.haverland@noaa.gov">tim.haverland@noaa.gov</a>>
                wrote:<br>
                >>>>>>><br>
                >>>>>>> yes, response header says:<br>
                >>>>>>><br>
                >>>>>>>
                Access-Control-Allow-Origin:<br>
                >>>>>>> *.<a moz-do-not-send="true"
                  href="http://noaa.gov" target="_blank">noaa.gov</a><br>
                >>>>>>><br>
                >>>>>>><br>
                >>>>>>><br>
                >>>>>>> On Tue, Jun 18, 2013 at
                1:32 PM, Micah Wengren - NOAA Federal<br>
                >>>>>>> <<a
                  moz-do-not-send="true"
                  href="mailto:micah.wengren@noaa.gov">micah.wengren@noaa.gov</a>>
                wrote:<br>
                >>>>>>>><br>
                >>>>>>>> Hi Tim,<br>
                >>>>>>>><br>
                >>>>>>>> I don't know what
                bearing ports have on CORS.  Everything from<br>
                >>>>>>>> <a
                  moz-do-not-send="true" href="http://noaa.gov"
                  target="_blank">noaa.gov</a><br>
                >>>>>>>> should be allowed
                though.  If you examine http headers with firebug<br>
                >>>>>>>> or<br>
                >>>>>>>> something you should be
                able to see the rule Chi added in the header<br>
                >>>>>>>> list.<br>
                >>>>>>>> I believe he would have
                added it for both http and https, but I'd<br>
                >>>>>>>> have to<br>
                >>>>>>>> check. Not at my
                machine right now. It's more important for http in<br>
                >>>>>>>> this<br>
                >>>>>>>> case...<br>
                >>>>>>>><br>
                >>>>>>>> Micah<br>
                >>>>>>>><br>
                >>>>>>>><br>
                >>>>>>>><br>
                >>>>>>>> On Tuesday, June 18,
                2013, Tim Haverland - NOAA Federal<br>
                >>>>>>>> <<a
                  moz-do-not-send="true"
                  href="mailto:tim.haverland@noaa.gov">tim.haverland@noaa.gov</a>>
                wrote:<br>
                >>>>>>>>><br>
                >>>>>>>>> Micah, is CORS
                supported on the production version of geoserver?<br>
                >>>>>>>>> I'm<br>
                >>>>>>>>> trying to implement
                my map in our content management system, and<br>
                >>>>>>>>> get the<br>
                >>>>>>>>> following error:<br>
                >>>>>>>>> Origin <a
                  moz-do-not-send="true"
                  href="http://triggerfish2.nmfs.noaa.gov:9992"
                  target="_blank">http://triggerfish2.nmfs.noaa.gov:9992</a>
                is not allowed by<br>
                >>>>>>>>>
                Access-Control-Allow-Origin.<br>
                >>>>>>>>><br>
                >>>>>>>>> Maybe it's the port
                that's throwing things off?<br>
                >>>>>>>>> Tim<br>
                >>>>>>>>><br>
                >>>>>>>>> On Thu, Jun 13,
                2013 at 1:27 PM, Micah Wengren - NOAA Federal<br>
                >>>>>>>>> <<a
                  moz-do-not-send="true"
                  href="mailto:micah.wengren@noaa.gov">micah.wengren@noaa.gov</a>>
                wrote:<br>
                >>>>>>>>>><br>
                >>>>>>>>>> Hi Tim,<br>
                >>>>>>>>>><br>
                >>>>>>>>>> We have *.<a
                  moz-do-not-send="true" href="http://noaa.gov"
                  target="_blank">noaa.gov</a> enabled anyway for CORS
                support now.  If you<br>
                >>>>>>>>>> can<br>
                >>>>>>>>>> copy your
                openlayers page to your dev server and test it out and<br>
                >>>>>>>>>> let me know<br>
                >>>>>>>>>> if it works,
                that would be great. Whenever you get a chance, no<br>
                >>>>>>>>>> rush.<br>
                >>>>>>>>>><br>
                >>>>>><br>
                >>>>><br>
                >>>>><br>
                >>>>> --<br>
                >>>>> Tim Haverland<br>
                >>>>> Acting Operations Branch Chief<br>
                >>>>> NOAA Fisheries Office of Science
                and Technology<br>
                >>>>> 1315 East-West Highway<br>
                >>>>> SSMC3 Rm 12303<br>
                >>>>> Silver Spring, MD 20910<br>
                >>>>> <a moz-do-not-send="true"
                  href="tel:301-427-8137" value="+13014278137">301-427-8137</a><br>
                >>>>><br>
                >>>>><br>
                >>>><br>
                >>>><br>
                >>>> --<br>
                >>>> Tim Haverland<br>
                >>>> Acting Operations Branch Chief<br>
                >>>> NOAA Fisheries Office of Science and
                Technology<br>
                >>>> 1315 East-West Highway<br>
                >>>> SSMC3 Rm 12303<br>
                >>>> Silver Spring, MD 20910<br>
                >>>> <a moz-do-not-send="true"
                  href="tel:301-427-8137" value="+13014278137">301-427-8137</a><br>
                >>>><br>
                >>>>
                _______________________________________________<br>
                >>>> Open.ogc mailing list<br>
                >>>> <a moz-do-not-send="true"
                  href="mailto:Open.ogc@list.woc.noaa.gov">Open.ogc@list.woc.noaa.gov</a><br>
                >>>> <a moz-do-not-send="true"
                  href="https://list.woc.noaa.gov/cgi-bin/mailman/listinfo/open.ogc"
                  target="_blank">https://list.woc.noaa.gov/cgi-bin/mailman/listinfo/open.ogc</a><br>
                >>>><br>
                >>><br>
                >>><br>
                >><br>
                ><br>
                ><br>
                ><br>
                > --<br>
                > Tim Haverland<br>
                > Acting Operations Branch Chief<br>
                > NOAA Fisheries Office of Science and Technology<br>
                > 1315 East-West Highway<br>
                > SSMC3 Rm 12303<br>
                > Silver Spring, MD 20910<br>
                > <a moz-do-not-send="true" href="tel:301-427-8137"
                  value="+13014278137">301-427-8137</a><br>
                ><br>
                ><br>
                <br>
                <br>
                <br>
              </div>
            </div>
            <div class="HOEnZb">
              <div class="h5">--<br>
                Chi Y Kang<br>
                Principal Engineer<br>
                Phone: <a moz-do-not-send="true"
                  href="tel:301.628.5642" value="+13016285642">301.628.5642</a><br>
                Cell: <a moz-do-not-send="true" href="tel:240.338.1059"
                  value="+12403381059">240.338.1059</a><br>
              </div>
            </div>
          </blockquote>
        </div>
        <br>
        <br clear="all">
        <div><br>
        </div>
        -- <br>
        <div dir="ltr"><b style="background-color:rgb(255,255,255)">Tim
            Haverland</b>
          <div>Acting Operations Branch Chief</div>
          <div>NOAA Fisheries Office of Science and Technology</div>
          <div>1315 East-West Highway</div>
          <div>SSMC3 Rm 12303</div>
          <div>Silver Spring, MD 20910</div>
          <div>301-427-8137</div>
        </div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Open.ogc mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Open.ogc@list.woc.noaa.gov">Open.ogc@list.woc.noaa.gov</a>
<a class="moz-txt-link-freetext" href="https://list.woc.noaa.gov/cgi-bin/mailman/listinfo/open.ogc">https://list.woc.noaa.gov/cgi-bin/mailman/listinfo/open.ogc</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>