INNER CODE UNIT · TypeScript
getAllowedOrigins
eclaire-labs/eclaire · apps/backend/src/index.ts:56
const getAllowedOrigins = () => {
const origins = [config.services.frontendUrl, "http://frontend:3000"];
if (!config.isProduction) {
origins.push("http://localhost:3000", "http://127.0.0.1:3000");
}
return origins;
};
// Global body size limit (50 MB) to prevent memory exhaustion from oversized requests
app.use("*", bodyLimit({ maxSize: 50 * 1024 * 1024 }));
// CORS configuration with explicit allowed origins
app.use(
"*",
cors({
origin: getAllowedOrigins(),
credentials: true,
allowHeaders: ["Content-Type", "Authorization", "Cookie"],