summary refs log tree commit diff
path: root/src/api/middlewares/corsMiddleware.js
diff options
context:
space:
mode:
authorRory& <root@rory.gay>2025-05-28 09:17:55 +0200
committerRory& <root@rory.gay>2025-05-28 09:17:55 +0200
commit1cf9e271ccea793906f6848339f197a55132a174 (patch)
tree9a4e7e5459929579d206e2d72188b3634ff1153e /src/api/middlewares/corsMiddleware.js
parentBasic routing and express setup (diff)
downloadnodejs-final-assignment-1cf9e271ccea793906f6848339f197a55132a174.tar.xz
Move middlewares out of start.js
Diffstat (limited to 'src/api/middlewares/corsMiddleware.js')
-rw-r--r--src/api/middlewares/corsMiddleware.js25
1 files changed, 25 insertions, 0 deletions
diff --git a/src/api/middlewares/corsMiddleware.js b/src/api/middlewares/corsMiddleware.js
new file mode 100644

index 0000000..2d06d47 --- /dev/null +++ b/src/api/middlewares/corsMiddleware.js
@@ -0,0 +1,25 @@ +export function useCors(req, res, next) { + res.set( + "Content-security-policy", + "default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline';", + ); + + res.set("Access-Control-Allow-Origin", "*"); + res.set( + "Access-Control-Allow-Headers", + req.header("Access-Control-Request-Headers") || "*", + ); + res.set( + "Access-Control-Allow-Methods", + req.header("Access-Control-Request-Methods") || "*", + ); + + res.set("Access-Control-Allow-Credentials", "true"); + + // Handle preflight requests + if (req.method === "OPTIONS") { + return res.sendStatus(204); + } + + next(); +}