I am trying to enable CORS for an API built in CakePHP so that all requests are accessible with the following in the AppController:

public function beforeFilter()
{
    header("Access-Control-Allow-Origin: *");
}

Is this in the wrong place? As requests are still being blocked.

Update: It seems this does in fact work BUT because I am doing something like:

header('Content-Type: application/json');
echo json_encode(array('message'=>'Hello world!'));

In some of my methods it's acting as though it's overriding the header set the AppController so it's not appearing in the response for the JSON calls. Any ideas?

Update 2: Returning JSON like below, fixes the problem:

$this->response->type('json');
$this->response->body(json_encode(array('message'=>'Hello world!')));

So apparently using header() in Cake breaks previous headers?

Edit
Report