From f35026eb8f53eae204d33ede30be5b66cb937dfd Mon Sep 17 00:00:00 2001 From: mahdi purHosseini Date: Thu, 21 Sep 2023 14:26:24 +0330 Subject: [PATCH] feat: add cors --- .env.example | 42 ++++++++++++++++++++++++++++++++++++++++++ .values.yaml | 43 +++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 85 insertions(+) create mode 100644 .env.example diff --git a/.env.example b/.env.example new file mode 100644 index 00000000..0e4390bf --- /dev/null +++ b/.env.example @@ -0,0 +1,42 @@ +APP_KEY=base64:Qu9CD7ACn0YIwll0762CRhE0eElot8cPWJV4dTYoka0= +DB_USERNAME=root +DB_PASSWORD= +REDIS_PASSWORD=null +MAIL_MAILER=smtp +MAIL_HOST=smtp.mailtrap.io +MAIL_PORT=2525 +MAIL_USERNAME=null +MAIL_PASSWORD=null +MAIL_ENCRYPTION=null +MAIL_FROM_ADDRESS=null +MAIL_FROM_NAME="${APP_NAME}" +AWS_ACCESS_KEY_ID= +AWS_SECRET_ACCESS_KEY= +AWS_DEFAULT_REGION=us-east-1 +AWS_BUCKET= +PUSHER_APP_ID= +PUSHER_APP_KEY= +PUSHER_APP_SECRET= +PUSHER_APP_CLUSTER=mt1 +APP_NAME= +APP_ENV= +APP_DEBUG= +APP_URL= +LOG_CHANNEL= +BROADCAST_DRIVER= +CACHE_DRIVER= +QUEUE_CONNECTION= +SESSION_DRIVER= +SESSION_LIFETIME= +REDIS_HOST= +REDIS_PORT= +DB_CONNECTION= +DB_HOST= +DB_PORT= +DB_DATABASE= +SMS_WEBSERVICE= +MIX_APP_ROOT_API= +MIX_APP_CLIENT_ID= +MIX_APP_CLIENT_SECRET= +SMS_USERNAME= +SMS_PASSWORD= diff --git a/.values.yaml b/.values.yaml index 980336fd..34601b69 100644 --- a/.values.yaml +++ b/.values.yaml @@ -611,6 +611,49 @@ configMap: } location ~ \.php { + if ($request_method = 'OPTIONS' ) { + add_header 'Access-Control-Allow-Origin' '*' always; + add_header 'Access-Control-Allow-Credentials' 'true'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE'; + add_header 'Access-Control-Allow-Headers' + 'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type'; + add_header 'Access-Control-Max-Age' 10; + add_header 'Content-Type' 'text/plain charset=UTF-8'; + add_header 'Content-Length' 0; + return 204; + } + + if ($request_method = 'POST' ) { + add_header 'Access-Control-Allow-Origin' '*' always; + add_header 'Access-Control-Allow-Credentials' 'true'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE'; + add_header 'Access-Control-Allow-Headers' + 'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type'; + } + + if ($request_method = 'GET' ) { + add_header 'Access-Control-Allow-Origin' '*' always; + add_header 'Access-Control-Allow-Credentials' 'true'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE'; + add_header 'Access-Control-Allow-Headers' + 'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type'; + } + + if ($request_method = 'PUT' ) { + add_header 'Access-Control-Allow-Origin' '*' always; + add_header 'Access-Control-Allow-Credentials' 'true'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE'; + add_header 'Access-Control-Allow-Headers' + 'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type'; + } + + if ($request_method = 'DELETE' ) { + add_header 'Access-Control-Allow-Origin' '*' always; + add_header 'Access-Control-Allow-Credentials' 'true'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE'; + add_header 'Access-Control-Allow-Headers' + 'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type'; + } fastcgi_pass localhost:9000; fastcgi_split_path_info ^(.+\.php)(.*)$; include /etc/nginx/fastcgi_params;