AOSSIE-Org / AOSSIE-Org/DebateAI
Fix CORS preflight: Always return 200 JSON + correct headers for OPTIONS requests
- Ngôn ngữ chính
- TypeScript
- Star
- 84
- Fork
- 198
- Merge trung bình
- 2 ngày 19 giờ
- Pull request đã merge (30 ngày)
- 30
Mô tả
### Problem
Some frontend requests fail silently due to CORS preflight (OPTIONS) requests not returning CORS-safe JSON & headers.
When the browser sends an OPTIONS preflight, the backend does not respond with:
- 200 OK
- correct `Access-Control-*` headers
- JSON response
As a result, the browser blocks the real request before it hits the route.
### Reproduction
1. Make a cross-origin POST request from the frontend with Authorization header
2. Observe OPTIONS preflight request
3. Browser blocks request due to missing CORS-safe response
### Proposed Fix
Add a CORS middleware so that:
1. OPTIONS requests always respond with `200 OK`, JSON content, and required CORS headers
2. All routes include `Access-Control-Allow-Origin`, `Access-Control-Allow-Methods`, and `Access-Control-Allow-Headers` in responses
### Acceptance Criteria
- OPTIONS requests return HTTP 200
- Response includes valid CORS headers
- Response body is valid JSON
- Frontend requests no longer fail at preflight stage
### Benefits
- avoids silent CORS failures in browsers
- improves developer experience
- infra-level fix with no feature logic changes
Happy to submit a PR for this if the approach looks good.
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.