Ensure user sessions persist correctly and securely across the platform

Implements CORS and updates AuthContext to manage user authentication via cookie-based sessions.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 8fac8604-8776-4090-bf16-1e3d01acb719
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/9777c70b-fc38-4831-8d6b-78dfffe041b0/e43769e0-ea3b-4deb-b53a-a84e46de587b.jpg
This commit is contained in:
ghaddaditw
2025-06-08 14:51:14 +00:00
parent 2764931504
commit fbdc1ff1da
3 changed files with 34 additions and 3 deletions
+15
View File
@@ -5,6 +5,21 @@ import { setupVite, serveStatic, log } from "./vite";
const app = express();
app.set('trust proxy', true);
// CORS configuration for authentication
app.use((req, res, next) => {
res.header('Access-Control-Allow-Credentials', 'true');
res.header('Access-Control-Allow-Origin', req.headers.origin);
res.header('Access-Control-Allow-Methods', 'GET,PUT,POST,DELETE,OPTIONS');
res.header('Access-Control-Allow-Headers', 'Content-Type, Authorization, Content-Length, X-Requested-With');
if (req.method === 'OPTIONS') {
res.sendStatus(200);
} else {
next();
}
});
app.use(express.json());
app.use(express.urlencoded({ extended: false }));