add permissive CORS headers
This commit is contained in:
parent
31deaf3aa5
commit
a799e1ba1c
1 changed files with 18 additions and 0 deletions
|
|
@ -12,6 +12,24 @@ import { getIdFilters } from '@welshman/util'
|
|||
|
||||
export const server: express.Application = express()
|
||||
|
||||
// The browser hits /subscription with an Authorization header and Content-Type:
|
||||
// application/json, which triggers a CORS preflight. Answer it and allow the
|
||||
// configured origin so the client can register.
|
||||
const corsOrigin = process.env.CORS_ORIGIN ?? '*'
|
||||
|
||||
server.use((req: Request, res: Response, next: NextFunction) => {
|
||||
res.setHeader('Access-Control-Allow-Origin', corsOrigin)
|
||||
res.setHeader('Access-Control-Allow-Methods', 'GET,POST,DELETE,OPTIONS')
|
||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type,Authorization')
|
||||
res.setHeader('Access-Control-Max-Age', '86400')
|
||||
|
||||
if (req.method === 'OPTIONS') {
|
||||
return res.sendStatus(204)
|
||||
}
|
||||
|
||||
next()
|
||||
})
|
||||
|
||||
server.use(express.json())
|
||||
|
||||
server.use(express.static('web/dist'))
|
||||
|
|
|
|||
Loading…
Reference in a new issue