all origin allowed for cors
This commit is contained in:
@@ -18,7 +18,7 @@ const {error_handler} = require('./src/middlewares/error_handler')
|
|||||||
|
|
||||||
app.options(options)
|
app.options(options)
|
||||||
|
|
||||||
app.use(cors({origin: "*"})) // for any address
|
app.use(cors)
|
||||||
|
|
||||||
app.use(helmet())
|
app.use(helmet())
|
||||||
|
|
||||||
|
|||||||
@@ -7,12 +7,13 @@ const options = (req, res) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const cors = (req, res, next) => {
|
const cors = (req, res, next) => {
|
||||||
const {origin} = req.headers
|
// const {origin} = req.headers
|
||||||
if (allowed_cors.includes(origin)) {
|
// if (allowed_cors.includes(origin)) {
|
||||||
res.setHeader('Access-Control-Allow-Origin', origin)
|
// res.setHeader('Access-Control-Allow-Origin', origin)
|
||||||
}
|
// }
|
||||||
res.setHeader('Access-Control-Allow-Credentials', true)
|
res.setHeader('Access-Control-Allow-Credentials', true)
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'X-Requested-With,content-type')
|
res.setHeader('Access-Control-Allow-Headers', 'X-Requested-With,content-type')
|
||||||
|
res.setHeader("Access-Control-Allow-Origin", "*")
|
||||||
next()
|
next()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user