headers->set('Access-Control-Allow-Origin', '*'); $response->headers->set('Access-Control-Allow-Methods', 'GET, POST, PUT, PATCH, DELETE, OPTIONS'); $response->headers->set('Access-Control-Allow-Headers', 'Content-Type, Authorization, X-Requested-With, Accept, X-CSRF-TOKEN'); $response->headers->set('Access-Control-Max-Age', '86400'); // 24 hours // Handle preflight OPTIONS requests if ($request->isMethod('OPTIONS')) { return response()->json('', 200); } return $response; } }