Update cors agar bisa diakases server staging dan localhost

This commit is contained in:
mikael-zakaria 2025-07-14 15:36:21 +07:00
parent 8f8769bcee
commit efce70e5a2
2 changed files with 5 additions and 4 deletions

View File

@ -34,7 +34,7 @@ class Cors extends BaseConfig
* - ['http://localhost:8080'] * - ['http://localhost:8080']
* - ['https://www.example.com'] * - ['https://www.example.com']
*/ */
'allowedOrigins' => [], 'allowedOrigins' => ['http://localhost:5173', 'https://clqms01.services-summit.my.id/'],
/** /**
* Origin regex patterns for the `Access-Control-Allow-Origin` header. * Origin regex patterns for the `Access-Control-Allow-Origin` header.
@ -57,7 +57,7 @@ class Cors extends BaseConfig
* *
* @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Credentials * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Credentials
*/ */
'supportsCredentials' => false, 'supportsCredentials' => true,
/** /**
* Set headers to allow. * Set headers to allow.
@ -68,7 +68,7 @@ class Cors extends BaseConfig
* *
* @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Headers * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Headers
*/ */
'allowedHeaders' => [], 'allowedHeaders' => ['Content-Type', 'Authorization', 'X-Requested-With'],
/** /**
* Set headers to expose. * Set headers to expose.
@ -93,7 +93,7 @@ class Cors extends BaseConfig
* *
* @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Methods * @see https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Methods
*/ */
'allowedMethods' => [], 'allowedMethods' => ['GET', 'POST', 'PUT', 'DELETE', 'OPTIONS'],
/** /**
* Set how many seconds the results of a preflight request can be cached. * Set how many seconds the results of a preflight request can be cached.

View File

@ -69,6 +69,7 @@ class Filters extends BaseFilters
*/ */
public array $globals = [ public array $globals = [
'before' => [ 'before' => [
'cors',
// 'honeypot', // 'honeypot',
// 'csrf', // 'csrf',
// 'invalidchars', // 'invalidchars',