cors fixed
This commit is contained in:
57
main.go
57
main.go
@@ -23,6 +23,20 @@ import (
|
||||
"gorm.io/gorm"
|
||||
)
|
||||
|
||||
// corsSettings is a function so it can be tested.
|
||||
//
|
||||
// Inline, it could only be checked by starting the server and pointing a real
|
||||
// browser at it — which is how the missing Authorization header reached
|
||||
// production in the first place.
|
||||
func corsSettings() cors.Config {
|
||||
return cors.Config{
|
||||
AllowHeaders: "Origin,Content-Type,Accept,Content-Length,Accept-Language,Accept-Encoding,Connection,Authorization",
|
||||
AllowOrigins: "*",
|
||||
AllowCredentials: false,
|
||||
AllowMethods: "GET,POST,HEAD,PUT,DELETE,PATCH,OPTIONS",
|
||||
}
|
||||
}
|
||||
|
||||
func main() {
|
||||
// Loads `.env.<APP_ENV>` (default `.env.local`) and `.env`, then checks
|
||||
// every required setting at once. Nothing below runs against a half
|
||||
@@ -31,12 +45,43 @@ func main() {
|
||||
|
||||
app := fiber.New()
|
||||
|
||||
app.Use(cors.New(cors.Config{
|
||||
AllowHeaders: "Origin,Content-Type,Accept,Content-Length,Accept-Language,Accept-Encoding,Connection,Access-Control-Allow-Origin",
|
||||
AllowOrigins: "*",
|
||||
AllowCredentials: true,
|
||||
AllowMethods: "GET,POST,HEAD,PUT,DELETE,PATCH,OPTIONS",
|
||||
}))
|
||||
// Cross-origin access.
|
||||
//
|
||||
// The console is served from app.nearledaily.com and calls this host
|
||||
// directly, so every request it makes is cross-origin and the browser
|
||||
// decides whether to allow it from the headers below.
|
||||
//
|
||||
// ── Authorization has to be listed ──────────────────────────────────────
|
||||
//
|
||||
// It was not, and adding the session token to the console broke every call
|
||||
// the moment it shipped. A request carrying `Authorization` is no longer a
|
||||
// "simple" request, so the browser stops and asks permission first — and the
|
||||
// answer has to name that header explicitly. It was never needed before
|
||||
// because the console sent nothing but `Accept` and `Content-Type`.
|
||||
//
|
||||
// The failure is worth recognising again: the preflight returns 204 and
|
||||
// looks healthy in a terminal, the server logs nothing, and only the browser
|
||||
// refuses. `curl` cannot reproduce it, because curl does not enforce CORS.
|
||||
//
|
||||
// ── Credentials off, wildcard on ────────────────────────────────────────
|
||||
//
|
||||
// `AllowOrigins: "*"` with `AllowCredentials: true` is not a valid pair: a
|
||||
// browser rejects a credentialed response that carries a wildcard origin.
|
||||
// That combination was here already and was harmless only because nothing
|
||||
// used credentials — it would have become a second, identical-looking bug
|
||||
// the day anything did.
|
||||
//
|
||||
// Credentials means cookies and TLS client certs, and this backend uses
|
||||
// neither: authentication is a Bearer token, which is an ordinary header and
|
||||
// needs no credentialed mode. Nothing in the console, the app or the POS
|
||||
// sets `credentials: 'include'`, so turning it off costs nothing and makes
|
||||
// the pair legal.
|
||||
//
|
||||
// The wildcard itself is worth revisiting — it lets any site on the internet
|
||||
// call this API from a browser, and the tenant guard is what stops that
|
||||
// mattering. Narrowing it to the known console origins is a separate change,
|
||||
// and one that breaks local development if the list is got wrong.
|
||||
app.Use(cors.New(corsSettings()))
|
||||
|
||||
fmt.Println("🌐 Connecting to databases...")
|
||||
db.Connect(cfg)
|
||||
|
||||
Reference in New Issue
Block a user