add permissive CORS headers

This commit is contained in:
mplorentz 2026-08-20 12:42:31 -04:00
parent 31deaf3aa5
commit a799e1ba1c

View file

@ -12,6 +12,24 @@ import { getIdFilters } from '@welshman/util'
export const server: express.Application = express()
// The browser hits /subscription with an Authorization header and Content-Type:
// application/json, which triggers a CORS preflight. Answer it and allow the
// configured origin so the client can register.
const corsOrigin = process.env.CORS_ORIGIN ?? '*'
server.use((req: Request, res: Response, next: NextFunction) => {
res.setHeader('Access-Control-Allow-Origin', corsOrigin)
res.setHeader('Access-Control-Allow-Methods', 'GET,POST,DELETE,OPTIONS')
res.setHeader('Access-Control-Allow-Headers', 'Content-Type,Authorization')
res.setHeader('Access-Control-Max-Age', '86400')
if (req.method === 'OPTIONS') {
return res.sendStatus(204)
}
next()
})
server.use(express.json())
server.use(express.static('web/dist'))