Commit 156b6ff
committed
fix(api): implement production-ready cors in error handler
The errorHandler middleware was not adding CORS headers to error
responses in a production-ready way. This caused browsers to block
client-side applications from reading the response body, resulting in
generic network errors instead of specific API error messages.
This change refactors the errorHandler to use an environment-aware
helper function. It now checks for a `CORS_ALLOWED_ORIGIN` environment
variable for production and falls back to allowing any `localhost`
origin for development. This aligns the error response behavior with
the main CORS middleware and the project's documentation, fixing the bug.1 parent 95ac0af commit 156b6ff
File tree
2 files changed
+26
-9
lines changed- lib/src
- config
- middlewares
2 files changed
+26
-9
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
82 | 89 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
7 | 8 | | |
8 | 9 | | |
9 | 10 | | |
| |||
108 | 109 | | |
109 | 110 | | |
110 | 111 | | |
111 | | - | |
112 | | - | |
113 | | - | |
114 | | - | |
115 | | - | |
116 | | - | |
117 | | - | |
118 | | - | |
119 | | - | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
120 | 130 | | |
121 | 131 | | |
122 | 132 | | |
| |||
0 commit comments