Skip to content

CORS Setup (Cross-Origin Resource Sharing) #29

Description

@taitelee

Problem

By default, web browsers block scripts (like JavaScript in a dashboard) from making requests to an API if that API is on a different domain. For instance if the dashboard is at dashboard.wavehouse.com and the API is hosted at api.wavehouse.com, the browser will stop the request for security reasons.

Proposed Solution

We should implement middleware (likely in internal/api/router.go) that tells the browser: "It is okay to let these specific websites talk to me."

  • We can possibly add whitelisted origins to our config (config.go and yaml) and access those origins from there.
  • For Development: We explicitly allow http://localhost:3000 (or similar) so we can build the front-end locally without the browser running into security errors.

Alternatives Considered

None

Additional Context

None

Activity

  1. added theissue type on Apr 16, 2026
  2. changed the title [-][feature] CORS Setup (Cross-Origin Resource Sharing)[/-] [+]CORS Setup (Cross-Origin Resource Sharing)[/+] on Apr 16, 2026
  3. self-assigned this
    on Apr 20, 2026
  4. moved this from Backlog to Ready in WaveHouse Task Boardon Apr 20, 2026
  5. moved this from Ready to In progress in WaveHouse Task Boardon Apr 21, 2026
  6. moved this from In progress to Backlog in WaveHouse Task Boardon Apr 30, 2026
  7. moved this from Backlog to Ready in WaveHouse Task Boardon May 12, 2026
  8. moved this from Ready to In progress in WaveHouse Task Boardon May 12, 2026
  9. moved this from In progress to In review in WaveHouse Task Boardon May 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions