Access control allow. Access-control-allow-origin. header("access-control-allow-origin:. header("access-control-allow-header: *");. xss код.