<div dir="ltr"><span style="font-size:12.8000001907349px">We're trying to integrate our (optional shibboleth login) non-prod website on </span><a href="https://dartbbncdevv3.dsc.umich.edu/" target="_blank" style="font-size:12.8000001907349px">https://dartbbncdevv3.dsc.umich.edu</a><span style="font-size:12.8000001907349px"> with our new non-prod (shibboleth protected) rest api on </span><a href="https://api-np.dev.umich.edu/" target="_blank" style="font-size:12.8000001907349px">https://api-np.dev.umich.edu</a><span style="font-size:12.8000001907349px"> and are finding that the website's ajax requests are getting not authorized responses (403s) from the new api. </span><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px">We've gotten public endpoints from the new api to work with the non-prod website, but we're thinking the CORS ajax requests probably need additional headers on them to be able to access the shibboleth protected endpoints. Has anyone already figured this out? We'd really appreciate any advice on this.</div><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px"><span style="font-size:12.8000001907349px">Our aim is to have the non-prod website keep the admin pages, but move the api endpoints it relies on to a new api. Ultimately if CORS ajax is not supported by shibboleth we may have to move the admin pages to the same domain as the new api, but we are trying to avoid that move because the website has a lot of public pages also that we don't want to separate or lose the known public domain name.</span><br clear="all" style="font-size:12.8000001907349px"><div style="font-size:12.8000001907349px"></div></div><div><div class="gmail_signature"><div><br></div><div>-Luke</div><div><a value="+17346042271">734.604.2271</a></div></div></div>
</div>