From 308bab8a3c40b4cd8a88d049f2936cb7f5fb4feb Mon Sep 17 00:00:00 2001 From: Elian Doran Date: Sun, 22 Mar 2026 20:53:19 +0200 Subject: [PATCH] fix(server): CORS for syncing with standalone --- apps/server/src/app.ts | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/apps/server/src/app.ts b/apps/server/src/app.ts index d38dddf9ce..0814f7f075 100644 --- a/apps/server/src/app.ts +++ b/apps/server/src/app.ts @@ -38,9 +38,10 @@ export default async function buildApp() { app.set("view engine", "ejs"); app.use((req, res, next) => { - // set CORS header + // set CORS headers if (config["Network"]["corsAllowOrigin"]) { res.header("Access-Control-Allow-Origin", config["Network"]["corsAllowOrigin"]); + res.header("Access-Control-Allow-Credentials", "true"); } if (config["Network"]["corsAllowMethods"]) { res.header("Access-Control-Allow-Methods", config["Network"]["corsAllowMethods"]); @@ -49,6 +50,12 @@ export default async function buildApp() { res.header("Access-Control-Allow-Headers", config["Network"]["corsAllowHeaders"]); } + // Handle preflight OPTIONS requests + if (req.method === "OPTIONS" && config["Network"]["corsAllowOrigin"]) { + res.sendStatus(204); + return; + } + res.locals.t = t; return next(); });