Access-Control-Allow-Origin: <origin header value> Access-Control-Allow-Credentials: trueThis HTTP header allows an ads player on any origin to read the VAST response from the ad server origin. The value of
Access-Control-Allow-Origin:should be the value of the
Originheader sent with the ad request. The
Access-Control-Allow-Credentials:header will ensure that cookies will be sent and received properly.
For more information, refer to the W3C Draft Specification on Cross-Origin Resource Sharing