httpd duplicate Access-Control-Allow-Origin with “Header always set”
I am trying to enable CORS on my server. It hosts both an Apache HTTPD and an Apache Tomee. HTTPD is configured as: SetEnvIf Origin "^https://(.+\.)?my-domain.com$" allowed_origin=$0 Header always set Access-Control-Allow-Origin %{allowed_origin}e env=allowed_origin Header set Access-Control-Allow-Credentials "true" Header set Access-Control-Allow-Methods "GET, POST, OPTIONS, HEAD, PUT, DELETE, PATCH" Header set Access-Control-Allow-Headers "accept,x-requested-method,origin,x-requested-with,x-request,cache-control,content-type" Header set Access-Control-Max-Age "600" and my Tomee web XML :