add permissive CORS headers
This commit is contained in:
parent
31deaf3aa5
commit
a799e1ba1c
1 changed files with 18 additions and 0 deletions
|
|
@ -12,6 +12,24 @@ import { getIdFilters } from '@welshman/util'
|
||||||
|
|
||||||
export const server: express.Application = express()
|
export const server: express.Application = express()
|
||||||
|
|
||||||
|
// The browser hits /subscription with an Authorization header and Content-Type:
|
||||||
|
// application/json, which triggers a CORS preflight. Answer it and allow the
|
||||||
|
// configured origin so the client can register.
|
||||||
|
const corsOrigin = process.env.CORS_ORIGIN ?? '*'
|
||||||
|
|
||||||
|
server.use((req: Request, res: Response, next: NextFunction) => {
|
||||||
|
res.setHeader('Access-Control-Allow-Origin', corsOrigin)
|
||||||
|
res.setHeader('Access-Control-Allow-Methods', 'GET,POST,DELETE,OPTIONS')
|
||||||
|
res.setHeader('Access-Control-Allow-Headers', 'Content-Type,Authorization')
|
||||||
|
res.setHeader('Access-Control-Max-Age', '86400')
|
||||||
|
|
||||||
|
if (req.method === 'OPTIONS') {
|
||||||
|
return res.sendStatus(204)
|
||||||
|
}
|
||||||
|
|
||||||
|
next()
|
||||||
|
})
|
||||||
|
|
||||||
server.use(express.json())
|
server.use(express.json())
|
||||||
|
|
||||||
server.use(express.static('web/dist'))
|
server.use(express.static('web/dist'))
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue