Fix CORS handling across API - #1
Merged
Merged
Conversation
Member
Greptile SummaryAdds consistent CORS handling throughout the API.
Confidence Score: 5/5The PR appears safe to merge, with consistent CORS coverage across all reachable response paths. The new wrapper receives mutable locally constructed responses, all response branches include the origin header, and the global preflight method list is valid even though individual resources implement different subsets.
|
| Filename | Overview |
|---|---|
| src/index.ts | Centralizes simple-response CORS decoration, expands preflight methods, and moves preflight handling ahead of route dispatch without introducing an identified defect. |
Reviews (1): Last reviewed commit: "Fix CORS handling across API" | Re-trigger Greptile
Member
|
hmmm interesting, I was concerned about the ordering considering there are new methods and I didn't know if it would cause ww3 if some of the methods on some routes being advertised wrong would be a problem but ig not, merging! |
Contributor
Author
|
Yeah that was the one part I double-checked too 😄 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes CORS handling across the API so browser clients can correctly use authenticated endpoints.
Changes
OPTIONSrequests before endpoint routing.PUTandDELETEinAccess-Control-Allow-Methods.Access-Control-Allow-Originconsistently to API responses, including errors and204responses.This keeps the existing authentication and API behavior unchanged while making CORS handling consistent across
/authorize,/users, and asset endpoints.