fix(api): allow multiple cors origins
This commit is contained in:
@@ -93,8 +93,19 @@ const startServer = async () => {
|
|||||||
);
|
);
|
||||||
|
|
||||||
if (isPrivatePath) {
|
if (isPrivatePath) {
|
||||||
|
// Allow multiple dashboard domains
|
||||||
|
const allowedOrigins = [
|
||||||
|
process.env.NEXT_PUBLIC_DASHBOARD_URL,
|
||||||
|
...(process.env.API_CORS_ORIGINS?.split(',') ?? []),
|
||||||
|
].filter(Boolean);
|
||||||
|
|
||||||
|
const origin = req.headers.origin;
|
||||||
|
const isAllowed = origin && allowedOrigins.includes(origin);
|
||||||
|
|
||||||
|
logger.info('Allowed origins', { allowedOrigins, origin, isAllowed });
|
||||||
|
|
||||||
return callback(null, {
|
return callback(null, {
|
||||||
origin: process.env.NEXT_PUBLIC_DASHBOARD_URL,
|
origin: isAllowed ? origin : false,
|
||||||
credentials: true,
|
credentials: true,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user