fix cors with helmet
This commit is contained in:
parent
2e98fa7f2d
commit
fce084f590
Binary file not shown.
@ -11,16 +11,13 @@ const prisma = new PrismaClient();
|
|||||||
|
|
||||||
const app: Express = express();
|
const app: Express = express();
|
||||||
app.use(express.json());
|
app.use(express.json());
|
||||||
app.use(helmet());
|
|
||||||
|
|
||||||
// Allow CORS in dev mode.
|
|
||||||
if (process.env.ENVIRONMENT == "dev") {
|
|
||||||
app.use(
|
app.use(
|
||||||
cors({
|
helmet({
|
||||||
origin: "*",
|
crossOriginResourcePolicy: {
|
||||||
|
policy: process.env.ENVIRONMENT == "dev" ? "cross-origin" : "same-origin",
|
||||||
|
},
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
}
|
|
||||||
|
|
||||||
// Apply rate limiting
|
// Apply rate limiting
|
||||||
const postLimiter = rateLimit({
|
const postLimiter = rateLimit({
|
||||||
|
Loading…
Reference in New Issue
Block a user