add CORS header with nginx
server {
# ...
# support some sub domains
# `add_header` is not allowed in `server`, so I did the hack.
if ($http_origin ~* "^https?://[\w\-]+\.example\.com$") {
set $allowed_origin $http_origin;
}
add_header "Access-Control-Allow-Origin" $allowed_origin;
# ...
}