Handling CORS with Nginx
mattlicense.co.uk
mattlicense.co.uk
IE9's limitations are also in spec, and again its behavior is for a good reason. Specifically GET and POST don't need to be preflighted and so webapps need to be prepared for the case where a hostile post request comes from a disallowed referrer (which can't be manipulated through javascript). Other methods do need to be preflighted so browsers that are unable to do that are not allowed to send cross-origin PUT,DELETE, etc. In fact most of the "frustrating" things MS does (e.g. disallowing cross scheme AJAX) are well thought out and if you don't understand why they make sense there is a good chance that you are creating security vulnerabilities.
In this case