Skip to content

Commit

Permalink
fix: do not add localhost to CORS
Browse files Browse the repository at this point in the history
Don't add localhost, as it is not needed.
  • Loading branch information
tkurki committed Oct 10, 2023
1 parent 53a12f0 commit becf29d
Showing 1 changed file with 5 additions and 1 deletion.
6 changes: 5 additions & 1 deletion src/cors.ts
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,11 @@ export const handleAdminUICORSOrigin = (
securityConfig.allowedCorsOrigins.length > 0
) {
allowedCorsOrigins = securityConfig.allowedCorsOrigins?.split(',')
if (allowedCorsOrigins.indexOf(securityConfig.adminUIOrigin) === -1) {
const adminUIOriginUrl = new URL(securityConfig.adminUIOrigin)
if (
allowedCorsOrigins.indexOf(securityConfig.adminUIOrigin) === -1 &&
adminUIOriginUrl.hostname !== 'localhost'
) {
allowedCorsOrigins.push(securityConfig.adminUIOrigin)
}
}
Expand Down

0 comments on commit becf29d

Please sign in to comment.