summary refs log tree commit diff
path: root/src/api/middlewares/corsMiddleware.js
diff options
context:
space:
mode:
Diffstat (limited to 'src/api/middlewares/corsMiddleware.js')
-rw-r--r--src/api/middlewares/corsMiddleware.js38
1 files changed, 19 insertions, 19 deletions
diff --git a/src/api/middlewares/corsMiddleware.js b/src/api/middlewares/corsMiddleware.js

index 2d06d47..f64dd32 100644 --- a/src/api/middlewares/corsMiddleware.js +++ b/src/api/middlewares/corsMiddleware.js
@@ -1,25 +1,25 @@ export function useCors(req, res, next) { - res.set( - "Content-security-policy", - "default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline';", - ); + res.set( + 'Content-security-policy', + "default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline';" + ); - res.set("Access-Control-Allow-Origin", "*"); - res.set( - "Access-Control-Allow-Headers", - req.header("Access-Control-Request-Headers") || "*", - ); - res.set( - "Access-Control-Allow-Methods", - req.header("Access-Control-Request-Methods") || "*", - ); + res.set('Access-Control-Allow-Origin', '*'); + res.set( + 'Access-Control-Allow-Headers', + req.header('Access-Control-Request-Headers') || '*' + ); + res.set( + 'Access-Control-Allow-Methods', + req.header('Access-Control-Request-Methods') || '*' + ); - res.set("Access-Control-Allow-Credentials", "true"); + res.set('Access-Control-Allow-Credentials', 'true'); - // Handle preflight requests - if (req.method === "OPTIONS") { - return res.sendStatus(204); - } + // Handle preflight requests + if (req.method === 'OPTIONS') { + return res.sendStatus(204); + } - next(); + next(); }