Problem
By default, web browsers block scripts (like JavaScript in a dashboard) from making requests to an API if that API is on a different domain. For instance if the dashboard is at dashboard.wavehouse.com and the API is hosted at api.wavehouse.com, the browser will stop the request for security reasons.
Proposed Solution
We should implement middleware (likely in internal/api/router.go) that tells the browser: "It is okay to let these specific websites talk to me."
- We can possibly add whitelisted origins to our config (config.go and yaml) and access those origins from there.
- For Development: We explicitly allow http://localhost:3000 (or similar) so we can build the front-end locally without the browser running into security errors.
Alternatives Considered
None
Additional Context
None
Problem
By default, web browsers block scripts (like JavaScript in a dashboard) from making requests to an API if that API is on a different domain. For instance if the dashboard is at dashboard.wavehouse.com and the API is hosted at api.wavehouse.com, the browser will stop the request for security reasons.
Proposed Solution
We should implement middleware (likely in internal/api/router.go) that tells the browser: "It is okay to let these specific websites talk to me."
Alternatives Considered
None
Additional Context
None