CORS headers for SSE

This commit is contained in:
2026-08-27 14:29:27 +02:00
parent c662626bd8
commit 62f952ac68
@@ -40,14 +40,20 @@ fun Application.module() {
val allowLocalhost = environment.config.propertyOrNull("ktor.cors.enableLocalhostOn")?.getString() ?: "0"
val safeOrigin = environment.config.propertyOrNull("ktor.cors.browserOrigin")?.getString()
install(CORS) {
// -- methods --
allowMethod(HttpMethod.Options)
allowMethod(HttpMethod.Delete)
allowMethod(HttpMethod.Patch)
allowMethod(HttpMethod.Get)
allowMethod(HttpMethod.Post)
// -- headers --
allowHeader(HttpHeaders.Accept)
allowHeader(HttpHeaders.Pragma)
allowHeader(HttpHeaders.Authorization)
allowHeader(HttpHeaders.ContentType)
allowHeader(HttpHeaders.CacheControl)
allowHeader(HttpHeaders.LastEventID)
// -- exposed headers --
exposeHeader(HttpHeaders.ContentType)
allowCredentials = true
allowNonSimpleContentTypes = true