AOSSIE-Org / AOSSIE-Org/DebateAI

Fix CORS preflight: Always return 200 JSON + correct headers for OPTIONS requests

未关闭
#258 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
TypeScript
星标
84
派生
198
平均合并
2 天 19 小时
30 天内合并 PR
30

描述

### Problem
Some frontend requests fail silently due to CORS preflight (OPTIONS) requests not returning CORS-safe JSON & headers.

When the browser sends an OPTIONS preflight, the backend does not respond with:
- 200 OK
- correct `Access-Control-*` headers
- JSON response

As a result, the browser blocks the real request before it hits the route.

### Reproduction

1. Make a cross-origin POST request from the frontend with Authorization header
2. Observe OPTIONS preflight request
3. Browser blocks request due to missing CORS-safe response

### Proposed Fix

Add a CORS middleware so that:
1. OPTIONS requests always respond with `200 OK`, JSON content, and required CORS headers
2. All routes include `Access-Control-Allow-Origin`, `Access-Control-Allow-Methods`, and `Access-Control-Allow-Headers` in responses

### Acceptance Criteria

- OPTIONS requests return HTTP 200
- Response includes valid CORS headers
- Response body is valid JSON
- Frontend requests no longer fail at preflight stage

### Benefits

- avoids silent CORS failures in browsers
- improves developer experience
- infra-level fix with no feature logic changes

Happy to submit a PR for this if the approach looks good.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。