Files
pr-preview/backend/src/lib/middlewares/cors.ts
T
space 40d484bede feat: initial scaffold - backend, frontend, Prisma schema, Docker
- Prisma schema: User, Session, RepoConfig, Preview, Job, WebhookToken, NoConfigComment, AdminSettings
- Backend: auth (login/logout/me/first-user setup), webhook handler with HMAC verification, EC2 service, SSH service, deploy pipeline, job queue worker, cron workers
- Frontend: Login with first-user detection, Dashboard, PreviewDetail with live log streaming, Settings, Repos config, Admin panel, SetupWizard, Privacy page
- Docker Compose and Dockerfile for self-hosted deployment
- Uses bcryptjs for Node 24 compatibility

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-25 00:18:08 +02:00

17 lines
747 B
TypeScript

import { Middleware } from "rjweb-server";
import { env } from "../env";
const ALLOWED_ORIGINS = new Set([env.PP_BASE_URL]);
export const corsMiddleware = new Middleware<{}, {}>("CORS Middleware", "1.0.0")
.httpRequest(async (_config, _server, _context, ctr) => {
const origin = ctr.headers.get("origin") || "";
if (ALLOWED_ORIGINS.has(origin) || env.NODE_ENV === "development") {
ctr.headers.set("Access-Control-Allow-Origin", origin || "*");
ctr.headers.set("Access-Control-Allow-Credentials", "true");
ctr.headers.set("Access-Control-Allow-Methods", "GET,POST,PUT,PATCH,DELETE,OPTIONS");
ctr.headers.set("Access-Control-Allow-Headers", "Content-Type,Authorization,X-Requested-With");
}
})
.export();