Skip to content

feat: enable global CORS for API routes - #28

Merged
zccz14 merged 4 commits into
mainfrom
feat/cors-open-all
Apr 19, 2026
Merged

zccz14 merged 4 commits into
mainfrom
feat/cors-open-all

Conversation

@zccz14

@zccz14 zccz14 commented Apr 19, 2026

Copy link
Copy Markdown
Owner

Summary

  • enable global Hono CORS for all API routes with origin "*"
  • add runtime tests for regular requests and OPTIONS preflight
  • document that CORS is for browser compatibility, not backend access control

Test Plan

  • pnpm --filter ./modules/api test

Copilot AI review requested due to automatic review settings April 19, 2026 19:16
@vercel

vercel Bot commented Apr 19, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cz-stack-web Ready Ready Preview, Comment Apr 19, 2026 7:16pm

@zccz14
zccz14 enabled auto-merge (squash) April 19, 2026 19:16
@zccz14
zccz14 merged commit bf02e86 into main Apr 19, 2026
6 checks passed
@zccz14
zccz14 deleted the feat/cors-open-all branch April 19, 2026 19:17

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Enables global CORS for the @cz-stack/api Hono app so browser clients can call API routes (including preflight OPTIONS) without per-route CORS handling, and documents that this is not an access-control mechanism.

Changes:

  • Register global hono/cors middleware in the API app entrypoint with origin: "*" for all routes.
  • Add runtime tests covering CORS headers on normal requests and OPTIONS preflight behavior.
  • Document the intended CORS boundary/expectations in API docs and add supporting spec/plan docs.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
modules/api/src/app.ts Adds global CORS middleware and clarifying comment in the app boundary.
modules/api/test/health-route.test.ts Adds integration tests for CORS headers and preflight handling.
docs/api/README.md Documents default CORS behavior and clarifies it’s not backend access control.
docs/superpowers/specs/2026-04-20-cors-open-all-design.md Adds a design/spec doc describing the global CORS decision and constraints.
docs/superpowers/plans/2026-04-20-cors-open-all.md Adds an implementation plan outlining the intended TDD steps and verification commands.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +122 to +124
await expect(response.json()).resolves.toEqual(
contractModule.openApiDocument,
);

Copilot AI Apr 19, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The new OpenAPI CORS test duplicates the existing “exposes the shared OpenAPI document” assertion that already deep-compares the full OpenAPI payload. Consider limiting this new test to just the CORS/header expectations (and avoid re-parsing / deep-equality of the full document) to reduce redundancy and brittleness as the OpenAPI document evolves.

Suggested change
await expect(response.json()).resolves.toEqual(
contractModule.openApiDocument,
);

Copilot uses AI. Check for mistakes.

This branch was successfully deployed

1 active deployment
Preview — 718a2afd Deployed Apr 19, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants