Files
apskel-pos-backend/internal/middleware/cors.go
T
efrilmandClaude Opus 5.5 4b7eddbd3e fix(cors): allow the Idempotency-Key header
The EnakGame client runs at its game_url, another origin than the API, so the
browser asks before POST /customer/enakgame/sessions. Idempotency-Key was not in
Access-Control-Allow-Headers, so the preflight refused it and a play could not
start. X-Idempotency-Key, the older name the backend also reads, is allowed too.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-09 22:58:02 +07:00

26 lines
688 B
Go

package middleware
import (
"github.com/gin-gonic/gin"
)
func CORS() gin.HandlerFunc {
return func(c *gin.Context) {
origin := c.Request.Header.Get("Origin")
if origin == "" {
origin = "*"
}
c.Header("Access-Control-Allow-Origin", origin)
c.Header("Access-Control-Allow-Credentials", "true")
c.Header("Access-Control-Allow-Headers", "Content-Type, Content-Length, Accept-Encoding, X-CSRF-Token, Authorization, accept, origin, Cache-Control, X-Requested-With, Idempotency-Key, X-Idempotency-Key")
c.Header("Access-Control-Allow-Methods", "POST, OPTIONS, GET, PUT, DELETE")
if c.Request.Method == "OPTIONS" {
c.AbortWithStatus(204)
return
}
c.Next()
}
}