diff --git a/config/middlewares.ts b/config/middlewares.ts index dea5b92..ec7d834 100644 --- a/config/middlewares.ts +++ b/config/middlewares.ts @@ -8,7 +8,7 @@ export default [ contentSecurityPolicy: { useDefaults: true, directives: { - "connect-src": ["'self'", "https:"], + "connect-src": ["'self'", "https:", "http:"], "img-src": [ "'self'", "data:", @@ -30,7 +30,15 @@ export default [ }, }, }, - "strapi::cors", + { + name: "strapi::cors", + config: { + origin: ["https://back.harmonylab.ovh", "https://www.choralsync.com"], + methods: ["GET", "POST", "PUT", "PATCH", "DELETE", "HEAD", "OPTIONS"], + headers: ["Content-Type", "Authorization", "Origin", "Accept"], + keepHeadersOnError: true, + }, +}, "strapi::poweredBy", "strapi::query", "strapi::body", diff --git a/config/server.ts b/config/server.ts index cc1fbe2..13e6b4c 100644 --- a/config/server.ts +++ b/config/server.ts @@ -4,6 +4,7 @@ export default ({ env }) => ({ host: env("HOST", "0.0.0.0"), port: env.int("PORT", 1337), proxy: true, + url: env('STRAPI_URL'), app: { keys: env.array("APP_KEYS"), },