HH-547: allow cross-origin widget requests (#126)
* HH-547: allow cross-origin widget requests * fix(HH-547): align production preflight with wildcard CORS --------- Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
@@ -1,9 +1,6 @@
|
||||
# GoChat production overrides. Secrets and public origins must come from the environment.
|
||||
# GoChat production overrides. Secrets must come from the environment.
|
||||
server:
|
||||
mode: "release"
|
||||
cors:
|
||||
allowed_origins: ["https://CHANGE_ME.example.com"]
|
||||
allow_credentials: true
|
||||
|
||||
database:
|
||||
dsn: "postgres://gochat:CHANGE_ME@postgres:5432/gochat_production?sslmode=disable"
|
||||
|
||||
@@ -10,14 +10,11 @@ server:
|
||||
max_header_bytes: 1048576
|
||||
trusted_proxies: [] # add explicit reverse-proxy IPs/CIDRs; XFF is ignored otherwise
|
||||
cors:
|
||||
allowed_origins: [] # empty = Allow-Origin:* in debug mode; production must list exact origins
|
||||
# Examples:
|
||||
# - "https://app.example.com"
|
||||
# - "*.example.com"
|
||||
allowed_origins: [] # retained for config compatibility; GoChat allows all origins
|
||||
allowed_methods: ["GET", "POST", "PUT", "DELETE", "PATCH", "OPTIONS"]
|
||||
allowed_headers: ["Origin", "Content-Type", "Accept", "Authorization", "X-Account-ID", "access-token", "client", "uid", "token-type", "expiry"]
|
||||
allowed_headers: ["Origin", "Content-Type", "Accept", "Authorization", "X-Account-ID", "X-Auth-Token", "X-Widget-Token", "X-Identifier-Hash", "access-token", "client", "uid", "token-type", "expiry"]
|
||||
expose_headers: ["Content-Length", "access-token", "client", "uid", "token-type", "expiry"]
|
||||
allow_credentials: false # set to true only if you need cookies/auth headers
|
||||
allow_credentials: false # retained for config compatibility; wildcard CORS does not use credentials
|
||||
max_age: 86400 # preflight cache duration in seconds
|
||||
|
||||
database:
|
||||
|
||||
Reference in New Issue
Block a user