Aaron Boushley 60aa52b753 Enable CORS requests to pass necessary headers.
To fully enable session deletion over CORS we need support for passing the
`X-Requested-With` header so that these requests can pass the `check-xhr` filter.

I also allowed the `X-CSRF-Token` to enable the alternative CSRF passing syntax.
2015-05-14 09:46:41 -07:00
..
2013-08-26 12:59:17 +10:00
2014-08-11 17:51:55 +10:00
2015-02-06 14:39:16 +11:00
2013-02-05 14:16:51 -05:00
2015-05-07 10:42:21 +10:00
2013-02-05 14:16:51 -05:00
2013-02-26 07:31:35 +03:00
2015-03-09 13:14:29 +11:00
2015-05-06 12:28:32 +10:00
2014-11-11 12:58:56 +11:00