cors fixed

This commit is contained in:
2026-09-24 11:38:46 +05:30
parent 9698de32d5
commit 294fb8ab93
4 changed files with 245 additions and 18 deletions

57
main.go
View File

@@ -23,6 +23,20 @@ import (
"gorm.io/gorm"
)
// corsSettings is a function so it can be tested.
//
// Inline, it could only be checked by starting the server and pointing a real
// browser at it — which is how the missing Authorization header reached
// production in the first place.
func corsSettings() cors.Config {
return cors.Config{
AllowHeaders: "Origin,Content-Type,Accept,Content-Length,Accept-Language,Accept-Encoding,Connection,Authorization",
AllowOrigins: "*",
AllowCredentials: false,
AllowMethods: "GET,POST,HEAD,PUT,DELETE,PATCH,OPTIONS",
}
}
func main() {
// Loads `.env.<APP_ENV>` (default `.env.local`) and `.env`, then checks
// every required setting at once. Nothing below runs against a half
@@ -31,12 +45,43 @@ func main() {
app := fiber.New()
app.Use(cors.New(cors.Config{
AllowHeaders: "Origin,Content-Type,Accept,Content-Length,Accept-Language,Accept-Encoding,Connection,Access-Control-Allow-Origin",
AllowOrigins: "*",
AllowCredentials: true,
AllowMethods: "GET,POST,HEAD,PUT,DELETE,PATCH,OPTIONS",
}))
// Cross-origin access.
//
// The console is served from app.nearledaily.com and calls this host
// directly, so every request it makes is cross-origin and the browser
// decides whether to allow it from the headers below.
//
// ── Authorization has to be listed ──────────────────────────────────────
//
// It was not, and adding the session token to the console broke every call
// the moment it shipped. A request carrying `Authorization` is no longer a
// "simple" request, so the browser stops and asks permission first — and the
// answer has to name that header explicitly. It was never needed before
// because the console sent nothing but `Accept` and `Content-Type`.
//
// The failure is worth recognising again: the preflight returns 204 and
// looks healthy in a terminal, the server logs nothing, and only the browser
// refuses. `curl` cannot reproduce it, because curl does not enforce CORS.
//
// ── Credentials off, wildcard on ────────────────────────────────────────
//
// `AllowOrigins: "*"` with `AllowCredentials: true` is not a valid pair: a
// browser rejects a credentialed response that carries a wildcard origin.
// That combination was here already and was harmless only because nothing
// used credentials — it would have become a second, identical-looking bug
// the day anything did.
//
// Credentials means cookies and TLS client certs, and this backend uses
// neither: authentication is a Bearer token, which is an ordinary header and
// needs no credentialed mode. Nothing in the console, the app or the POS
// sets `credentials: 'include'`, so turning it off costs nothing and makes
// the pair legal.
//
// The wildcard itself is worth revisiting — it lets any site on the internet
// call this API from a browser, and the tenant guard is what stops that
// mattering. Narrowing it to the known console origins is a separate change,
// and one that breaks local development if the list is got wrong.
app.Use(cors.New(corsSettings()))
fmt.Println("🌐 Connecting to databases...")
db.Connect(cfg)