पाठ 28 / 30
CORS और Security Headers
Cross-origin requests और response headers को safely control करें।
CORS (Cross-Origin Resource Sharing)
ब्राउज़र cross-origin requests को default रूप से block करते हैं। CORS headers ब्राउज़र को बताते हैं कि कौन-से origins आपके API को call कर सकते हैं।
CORS को configure करना
Allowed origins, methods, और headers को control करने के लिए @fastify/cors उपयोग करें।
import cors from '@fastify/cors';
await fastify.register(cors, {
origin: ['https://myapp.com', 'http://localhost:3001'],
methods: ['GET', 'POST', 'PUT', 'DELETE'],
credentials: true,
});