Repository navigation
feat: enable global CORS for API routes - #28
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Pull request overview
Enables global CORS for the @cz-stack/api Hono app so browser clients can call API routes (including preflight OPTIONS) without per-route CORS handling, and documents that this is not an access-control mechanism.
Changes:
- Register global
hono/corsmiddleware in the API app entrypoint withorigin: "*"for all routes. - Add runtime tests covering CORS headers on normal requests and
OPTIONSpreflight behavior. - Document the intended CORS boundary/expectations in API docs and add supporting spec/plan docs.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| modules/api/src/app.ts | Adds global CORS middleware and clarifying comment in the app boundary. |
| modules/api/test/health-route.test.ts | Adds integration tests for CORS headers and preflight handling. |
| docs/api/README.md | Documents default CORS behavior and clarifies it’s not backend access control. |
| docs/superpowers/specs/2026-04-20-cors-open-all-design.md | Adds a design/spec doc describing the global CORS decision and constraints. |
| docs/superpowers/plans/2026-04-20-cors-open-all.md | Adds an implementation plan outlining the intended TDD steps and verification commands. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| await expect(response.json()).resolves.toEqual( | ||
| contractModule.openApiDocument, | ||
| ); |
There was a problem hiding this comment.
The new OpenAPI CORS test duplicates the existing “exposes the shared OpenAPI document” assertion that already deep-compares the full OpenAPI payload. Consider limiting this new test to just the CORS/header expectations (and avoid re-parsing / deep-equality of the full document) to reduce redundancy and brittleness as the OpenAPI document evolves.
| await expect(response.json()).resolves.toEqual( | |
| contractModule.openApiDocument, | |
| ); |
Summary
Test Plan
pnpm --filter ./modules/api test