fix: add CORS headers to relay responses and OPTIONS method handling
This commit is contained in:
@@ -9,12 +9,15 @@ import {
|
|||||||
export const runtime = "edge";
|
export const runtime = "edge";
|
||||||
|
|
||||||
async function handler(req: Request): Promise<Response> {
|
async function handler(req: Request): Promise<Response> {
|
||||||
const ALLOWED_METHODS = new Set(["GET", "POST", "PUT", "DELETE", "PATCH", "HEAD", "OPTIONS"]);
|
if (req.method === "OPTIONS") {
|
||||||
|
return new Response(null, {
|
||||||
if (!ALLOWED_METHODS.has(req.method)) {
|
status: 204,
|
||||||
return new Response(JSON.stringify({ error: "Method not allowed" }), {
|
headers: {
|
||||||
status: 405,
|
"Access-Control-Allow-Origin": "*",
|
||||||
headers: { "content-type": "application/json" },
|
"Access-Control-Allow-Methods": "GET, POST, PUT, DELETE, PATCH, OPTIONS",
|
||||||
|
"Access-Control-Allow-Headers": "*",
|
||||||
|
"Access-Control-Max-Age": "86400",
|
||||||
|
},
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -27,7 +30,7 @@ async function handler(req: Request): Promise<Response> {
|
|||||||
JSON.stringify({ error: "Missing x-relay-target header" }),
|
JSON.stringify({ error: "Missing x-relay-target header" }),
|
||||||
{
|
{
|
||||||
status: 400,
|
status: 400,
|
||||||
headers: { "content-type": "application/json" },
|
headers: { "content-type": "application/json", "Access-Control-Allow-Origin": "*" },
|
||||||
},
|
},
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
@@ -37,7 +40,7 @@ async function handler(req: Request): Promise<Response> {
|
|||||||
JSON.stringify({ error: "Target domain not allowed" }),
|
JSON.stringify({ error: "Target domain not allowed" }),
|
||||||
{
|
{
|
||||||
status: 403,
|
status: 403,
|
||||||
headers: { "content-type": "application/json" },
|
headers: { "content-type": "application/json", "Access-Control-Allow-Origin": "*" },
|
||||||
},
|
},
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -95,6 +95,12 @@ export function createRelayResponse(response: Response): Response {
|
|||||||
headers.delete("transfer-encoding");
|
headers.delete("transfer-encoding");
|
||||||
headers.delete("connection");
|
headers.delete("connection");
|
||||||
headers.delete("keep-alive");
|
headers.delete("keep-alive");
|
||||||
|
|
||||||
|
// Add CORS for browser UI
|
||||||
|
headers.set("Access-Control-Allow-Origin", "*");
|
||||||
|
headers.set("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, PATCH, OPTIONS");
|
||||||
|
headers.set("Access-Control-Allow-Headers", "*");
|
||||||
|
|
||||||
return new Response(response.body, {
|
return new Response(response.body, {
|
||||||
status: response.status,
|
status: response.status,
|
||||||
headers,
|
headers,
|
||||||
|
|||||||
Reference in New Issue
Block a user