diff --git a/server/server.ts b/server/server.ts index 552569c..a2111cb 100644 --- a/server/server.ts +++ b/server/server.ts @@ -11,16 +11,13 @@ const prisma = new PrismaClient(); const app: Express = express(); app.use(express.json()); -app.use(helmet()); - -// Allow CORS in dev mode. -if (process.env.ENVIRONMENT == "dev") { - app.use( - cors({ - origin: "*", - }) - ); -} +app.use( + helmet({ + crossOriginResourcePolicy: { + policy: process.env.ENVIRONMENT == "dev" ? "cross-origin" : "same-origin", + }, + }) +); // Apply rate limiting const postLimiter = rateLimit({ diff --git a/webapp/src/lib/components/navbar/NavBar.svelte b/webapp/src/lib/components/navbar/NavBar.svelte index a8342e0..ac83a2e 100644 --- a/webapp/src/lib/components/navbar/NavBar.svelte +++ b/webapp/src/lib/components/navbar/NavBar.svelte @@ -5,7 +5,9 @@ >