# About writing the middleware

**URL:** <https://discourse.slimframework.com/t/about-writing-the-middleware/1516>\
**Category:** Questions\
**Created:** [May 26, 2017, 6:48am UTC](https://discourse.slimframework.com/t/about-writing-the-middleware/1516 "2017-05-26T06:48:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrewfjc](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@andrewfjc](https://discourse.slimframework.com/u/andrewfjc)\
**Post date:** [May 26, 2017, 6:48am UTC](https://discourse.slimframework.com/t/about-writing-the-middleware/1516/1 "2017-05-26T06:48:58Z")

</div>

Hello, I’m new in slim frame work.

I would like to know what is the different with the code below

```
$app->add(function ($request, $response, $next) {
    $response = $next($request, $response);
    return $response
            ->withHeader('Access-Control-Allow-Origin', 'https://mysite.com')
            ->withHeader('Access-Control-Allow-Headers', 'X-Requested-With, Content-Type, Accept, Origin, Authorization')
            ->withHeader('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
});

```

and this

```
$app->add(function ($request, $response, $next) {
    $response = $next($request, $response);
    $response->withHeader('Access-Control-Allow-Origin', 'https://mysite.com')
            ->withHeader('Access-Control-Allow-Headers', 'X-Requested-With, Content-Type, Accept, Origin, Authorization')
            ->withHeader('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
    return $response;
});

```

when I use the second statement, the header seem like won’t send out.

Can anybody give me help.

---

<div class="post-metadata">

**Author:** ![JupiterN](https://avatars.discourse-cdn.com/v4/letter/j/ac91a4/32.png) [@JupiterN](https://discourse.slimframework.com/u/JupiterN)\
**Post date:** [May 26, 2017, 10:33am UTC](https://discourse.slimframework.com/t/about-writing-the-middleware/1516/2 "2017-05-26T10:33:21Z")

</div>

The middleware can have code running before or after the response is sent out.  
In your case you want to change the reponse before its sent.  
Try the code bellow

```
$app->add(function ($request, $response, $next) {
    $response = $response
        ->withHeader('Access-Control-Allow-Origin', 'https://mysite.com')
        ->withHeader('Access-Control-Allow-Headers', 'X-Requested-With, Content-Type, Accept, Origin, Authorization')
        ->withHeader('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');

  return $next($request, $response);
});
```
