temp: pass all origins for cors
This commit is contained in:
+34
-30
@@ -37,40 +37,44 @@ async function bootstrap() {
|
|||||||
|
|
||||||
const configService = app.get(ConfigService);
|
const configService = app.get(ConfigService);
|
||||||
|
|
||||||
const origins = configService.get<string[]>('app.corsOrigins');
|
|
||||||
const subdomain = configService.get<string>('app.corsSubdomain');
|
|
||||||
|
|
||||||
console.log(subdomain, origins);
|
|
||||||
|
|
||||||
app.enableCors({
|
app.enableCors({
|
||||||
origin: (origin: string, callback: any) => {
|
origin: true,
|
||||||
if (!origin) {
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-unsafe-return, @typescript-eslint/no-unsafe-call
|
|
||||||
return callback(null, true);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (origins?.includes(origin)) {
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-unsafe-return, @typescript-eslint/no-unsafe-call
|
|
||||||
return callback(null, true);
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
|
||||||
const hostname = new URL(origin).hostname;
|
|
||||||
|
|
||||||
if (hostname === subdomain || hostname.endsWith(`.${subdomain}`)) {
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-unsafe-return, @typescript-eslint/no-unsafe-call
|
|
||||||
return callback(null, true);
|
|
||||||
}
|
|
||||||
} catch {
|
|
||||||
/* empty */
|
|
||||||
}
|
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-unsafe-call
|
|
||||||
callback(new Error('Not allowed by CORS'));
|
|
||||||
},
|
|
||||||
credentials: true,
|
credentials: true,
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// TODO: Uncomment
|
||||||
|
// const origins = configService.get<string[]>('app.corsOrigins');
|
||||||
|
// const subdomain = configService.get<string>('app.corsSubdomain');
|
||||||
|
|
||||||
|
// app.enableCors({
|
||||||
|
// origin: (origin: string, callback: any) => {
|
||||||
|
// if (!origin) {
|
||||||
|
// // eslint-disable-next-line @typescript-eslint/no-unsafe-return, @typescript-eslint/no-unsafe-call
|
||||||
|
// return callback(null, true);
|
||||||
|
// }
|
||||||
|
|
||||||
|
// if (origins?.includes(origin)) {
|
||||||
|
// // eslint-disable-next-line @typescript-eslint/no-unsafe-return, @typescript-eslint/no-unsafe-call
|
||||||
|
// return callback(null, true);
|
||||||
|
// }
|
||||||
|
|
||||||
|
// try {
|
||||||
|
// const hostname = new URL(origin).hostname;
|
||||||
|
|
||||||
|
// if (hostname === subdomain || hostname.endsWith(`.${subdomain}`)) {
|
||||||
|
// // eslint-disable-next-line @typescript-eslint/no-unsafe-return, @typescript-eslint/no-unsafe-call
|
||||||
|
// return callback(null, true);
|
||||||
|
// }
|
||||||
|
// } catch {
|
||||||
|
// /* empty */
|
||||||
|
// }
|
||||||
|
|
||||||
|
// // eslint-disable-next-line @typescript-eslint/no-unsafe-call
|
||||||
|
// callback(new Error('Not allowed by CORS'));
|
||||||
|
// },
|
||||||
|
// credentials: true,
|
||||||
|
// });
|
||||||
|
|
||||||
app.use(helmet());
|
app.use(helmet());
|
||||||
|
|
||||||
const config = new DocumentBuilder()
|
const config = new DocumentBuilder()
|
||||||
|
|||||||
Reference in New Issue
Block a user