Exposing the portal backend CORS reflect origin option to make local testing easier #260
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Exposing this already existing-config:
https://github.com/mojaloop/finance-portal-backend-service/blob/master/src/config/config.js#L38
to the chart. That controls whether the service responds with an
Access-Control-Allow-Origin
header that mirrors theOrigin
header in the request. When it does so, it means a UI served to the browser from any hostname can make requests to the backend- not just one served from the same hostname as the backend. It's standard browser security functionality- nothing implementation-specific.The specific use-case I'm trying to enable in this case is hosting a frontend on a developer machine and a backend in a cluster somewhere. I.e. frontend on localhost, backend on some other hostname.