updates on the customercontroller and the booking.go updates
This commit is contained in:
58
main.go
58
main.go
@@ -2,6 +2,7 @@ package main
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net/url"
|
||||
"os"
|
||||
"os/signal"
|
||||
"strings"
|
||||
@@ -31,6 +32,30 @@ import (
|
||||
// turned into an error by the recover middleware — into the same
|
||||
// {success, message} envelope the utils helpers emit, so clients never receive
|
||||
// Fiber's default plain-text error body.
|
||||
// isLoopbackOrigin reports whether an Origin header names this machine, on any
|
||||
// port. It exists for Flutter Web, whose dev server picks a fresh random port
|
||||
// on every launch — no fixed allowlist can name it in advance.
|
||||
//
|
||||
// Deliberately strict about what counts as loopback: the host must be exactly
|
||||
// localhost, 127.0.0.1 or [::1]. A prefix match would admit
|
||||
// http://localhost.attacker.com, which is a different machine entirely and is
|
||||
// precisely the mistake this kind of check usually makes.
|
||||
func isLoopbackOrigin(origin string) bool {
|
||||
u, err := url.Parse(origin)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
if u.Scheme != "http" && u.Scheme != "https" {
|
||||
return false
|
||||
}
|
||||
switch u.Hostname() {
|
||||
case "localhost", "127.0.0.1", "::1":
|
||||
return true
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
func errorHandler(c *fiber.Ctx, err error) error {
|
||||
code := fiber.StatusInternalServerError
|
||||
msg := "internal server error"
|
||||
@@ -107,10 +132,37 @@ func main() {
|
||||
// nil-pointer dereference in any handler takes the whole process down.
|
||||
app.Use(recover.New(recover.Config{EnableStackTrace: true}))
|
||||
|
||||
// CORS policy
|
||||
// CORS policy.
|
||||
//
|
||||
// The named list is production and the well-known dev-server ports. It cannot
|
||||
// cover local development on its own: `flutter run -d chrome` binds a RANDOM
|
||||
// high port on every launch (65256 one run, something else the next), so a
|
||||
// fixed allowlist misses it every time and the browser rejects the request
|
||||
// with PreflightMissingAllowOriginHeader before the handler is ever reached.
|
||||
//
|
||||
// AllowOriginsFunc is consulted only when the static list has already missed,
|
||||
// so it widens nothing in production — it just admits loopback origins on any
|
||||
// port while developing. It is NOT enabled when ENV=production: a live API
|
||||
// that accepts credentialed requests from any localhost page is a real, if
|
||||
// modest, hole — a developer visiting a hostile page served from their own
|
||||
// machine would have that page able to call this API as them.
|
||||
//
|
||||
// A wildcard is not an option regardless: AllowCredentials with
|
||||
// AllowOrigins "*" is rejected by the CORS spec, and Fiber panics on it.
|
||||
allowLoopbackOrigins := !strings.EqualFold(cfg.Env, "production")
|
||||
if allowLoopbackOrigins {
|
||||
utils.Info("CORS: loopback origins on any port are allowed (non-production)", "env", cfg.Env)
|
||||
}
|
||||
|
||||
app.Use(cors.New(cors.Config{
|
||||
AllowHeaders: "Origin,Content-Type,Accept,Authorization",
|
||||
AllowOrigins: "http://localhost:5173,http://localhost:5174,http://localhost:3000,http://localhost:3001,http://localhost:3002,http://localhost:8080,http://localhost:8081,https://doormile.com,https://www.doormile.com,https://admin.doormile.com,https://api.doormile.com,https://crm.doormile.com,https://console.doormile.com,https://app.doormile.com,https://hub.doormile.com",
|
||||
// Idempotency-Key is sent by the rider app on pickup-complete, payment
|
||||
// and the base handover. A browser client that could not send it would
|
||||
// lose retry safety on exactly the calls that most need it.
|
||||
AllowHeaders: "Origin,Content-Type,Accept,Authorization,Idempotency-Key",
|
||||
AllowOrigins: "http://localhost:5173,http://localhost:5174,http://localhost:3000,http://localhost:3001,http://localhost:3002,http://localhost:8080,http://localhost:8081,https://doormile.com,https://www.doormile.com,https://admin.doormile.com,https://api.doormile.com,https://crm.doormile.com,https://console.doormile.com,https://app.doormile.com,https://hub.doormile.com",
|
||||
AllowOriginsFunc: func(origin string) bool {
|
||||
return allowLoopbackOrigins && isLoopbackOrigin(origin)
|
||||
},
|
||||
AllowCredentials: true,
|
||||
AllowMethods: "GET,POST,PUT,DELETE,PATCH,OPTIONS",
|
||||
}))
|
||||
|
||||
Reference in New Issue
Block a user