# Thoughts about the HTTP headers

**URL:** <https://tech-community.robotics.abb.com/t/thoughts-about-the-http-headers/7461>\
**Category:** Developer Tools\
**Created:** [November 28, 2016, 8:34am UTC](https://tech-community.robotics.abb.com/t/thoughts-about-the-http-headers/7461 "2016-11-28T08:34:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![JonasUllberg](https://avatars.discourse-cdn.com/v4/letter/j/ecc23a/32.png) [@JonasUllberg](https://tech-community.robotics.abb.com/u/JonasUllberg)\
**Post date:** [November 28, 2016, 8:34am UTC](https://tech-community.robotics.abb.com/t/thoughts-about-the-http-headers/7461/1 "2016-11-28T08:34:27Z")

</div>

Hi, I have been using the new RW6 REST API for a while now and I think it works really well.

I was thinking that adding “Access-Control-Allow-Origin: \*” to the response headers would improve the API since it would allow for webpages to fetch data from the robot controller without needing to be served from it. Furthermore; although the character encoding is specified in the XML document, this information is not present in the JSON response and could be specified in the HTTP headers as well.

Cheers!

---

<div class="post-metadata">

**Author:** ![jf](https://avatars.discourse-cdn.com/v4/letter/j/c2a13f/32.png) [@jf](https://tech-community.robotics.abb.com/u/jf)\
**Post date:** [February 20, 2018, 5:11pm UTC](https://tech-community.robotics.abb.com/t/thoughts-about-the-http-headers/7461/2 "2018-02-20T17:11:39Z")

</div>

Facing the same issue.  
Yep, that would pave the way for modern React JS apps.  
Creating a backend server in python or .Net backend to interface with the robot controller’s REST interface feels really redundant, since the front-end can just as well consume the REST API.

---

<div class="post-metadata">

**Author:** ![jf](https://avatars.discourse-cdn.com/v4/letter/j/c2a13f/32.png) [@jf](https://tech-community.robotics.abb.com/u/jf)\
**Post date:** [March 2, 2018, 12:56pm UTC](https://tech-community.robotics.abb.com/t/thoughts-about-the-http-headers/7461/3 "2018-03-02T12:56:17Z")

</div>

Found the config file of the `REST` server running on the robot ( located: `/hd0a/05-102162/Products/RobotWare_6.05.0129/system/appweb.conf`). The server software used is [`EmbedThis`](https://www.embedthis.com/appweb/doc/).

The conf file suggest that authentication is configurable / could be turned off.  
That said, I ran into changing the file; seems additional permission is required and the usual ABB pwd’s didnt pan out here.

```auto
<Route ^/poll>
	AuthRealm "validusers@robapi.abb"
	AuthType digest
	AuthDigestQop auth
    WebSocketsProtocol robapi2_subscription
    AddFilter webSocketFilter
    SetHandler wsSubscription	
    RequestTimeout 72hours
#	InactivityTimeout 5hours
	WebSocketsPing 30seconds
</Route>

<Route ^\/fileservice(\/.*)*$>
	AuthRealm "validusers@robapi.abb"
	AuthType digest
	AuthDigestQop auth
	SetHandler rapi_filehandler
	Methods set ALL
</Route>

<Route ^\/docs(\/.*)*$>
	AuthRealm "validusers@robapi.abb"
	AuthType digest
	AuthDigestQop auth
	AddHandler fileHandler 
	Methods set GET
</Route>

<Route />
	AuthRealm "validusers@robapi.abb"
	AuthType digest
	AuthDigestQop auth
	SetHandler rapi_handler
	Methods set ALL
</Route>

```
