feat: allow CORS for any no-authed GET request in public

This commit is contained in:
zkldi
2022-07-12 12:49:29 +01:00
parent 460751525c
commit cedfa26612
2 changed files with 11093 additions and 4874 deletions
+11082 -4874
View File
File diff suppressed because it is too large Load Diff
+11
View File
@@ -52,6 +52,8 @@ const userSessionMiddleware = expressSession({
const app: Express = express();
if (Environment.nodeEnv !== "production" && IsNonEmptyString(ServerConfig.CLIENT_DEV_SERVER)) {
logger.warn(`Enabling CORS requests from ${ServerConfig.CLIENT_DEV_SERVER}.`, {
bootInfo: true,
@@ -82,6 +84,15 @@ if (Environment.nodeEnv !== "production" && IsNonEmptyString(ServerConfig.CLIENT
app.options("*", (req, res) => res.send());
}
} else {
app.use((req, res, next) => {
res.header("Access-Control-Allow-Origin", "*");
res.header("Access-Control-Allow-Credentials", "false");
res.header("Access-Control-Allow-Methods", "GET");
next();
});
app.options("*", (req, res) => res.send());
if (Environment.nodeEnv !== "test") {
logger.info("Enabling Helmet, as no CLIENT_DEV_SERVER was set, or we are in production.", {
bootInfo: true,