40d484bede
- Prisma schema: User, Session, RepoConfig, Preview, Job, WebhookToken, NoConfigComment, AdminSettings - Backend: auth (login/logout/me/first-user setup), webhook handler with HMAC verification, EC2 service, SSH service, deploy pipeline, job queue worker, cron workers - Frontend: Login with first-user detection, Dashboard, PreviewDetail with live log streaming, Settings, Repos config, Admin panel, SetupWizard, Privacy page - Docker Compose and Dockerfile for self-hosted deployment - Uses bcryptjs for Node 24 compatibility Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
17 lines
747 B
TypeScript
17 lines
747 B
TypeScript
import { Middleware } from "rjweb-server";
|
|
import { env } from "../env";
|
|
|
|
const ALLOWED_ORIGINS = new Set([env.PP_BASE_URL]);
|
|
|
|
export const corsMiddleware = new Middleware<{}, {}>("CORS Middleware", "1.0.0")
|
|
.httpRequest(async (_config, _server, _context, ctr) => {
|
|
const origin = ctr.headers.get("origin") || "";
|
|
if (ALLOWED_ORIGINS.has(origin) || env.NODE_ENV === "development") {
|
|
ctr.headers.set("Access-Control-Allow-Origin", origin || "*");
|
|
ctr.headers.set("Access-Control-Allow-Credentials", "true");
|
|
ctr.headers.set("Access-Control-Allow-Methods", "GET,POST,PUT,PATCH,DELETE,OPTIONS");
|
|
ctr.headers.set("Access-Control-Allow-Headers", "Content-Type,Authorization,X-Requested-With");
|
|
}
|
|
})
|
|
.export();
|