feat(config): make CORS allowed origins configurable via env (#697)
* feat(config): make CORS allowed origins configurable via env Replaces the hardcoded `origins` list in `src/main.py` with a new `CORSSettings` block (env prefix `CORS_`), exposed as `settings.CORS.ORIGINS`. Defaults match the prior hardcoded values, so self-hosted deployments behind custom domains can now whitelist their frontend without editing source. Documented in `.env.template` under a new CORS Settings section. * docs(config): add docstring to CORSSettings * refactor(config): inline CORS_ORIGINS into AppSettings Drop the dedicated CORSSettings nested model and expose CORS_ORIGINS directly on AppSettings. The CORS_ORIGINS env var keeps working as before since AppSettings has no env prefix.
This commit is contained in:
parent
9f26fdd2ea
commit
5a3b598cb4
|
|
@ -276,6 +276,13 @@ LLM_OPENAI_API_KEY=your-api-key-here
|
||||||
# CACHE_DEFAULT_TTL_SECONDS=300
|
# CACHE_DEFAULT_TTL_SECONDS=300
|
||||||
# CACHE_DEFAULT_LOCK_TTL_SECONDS=5
|
# CACHE_DEFAULT_LOCK_TTL_SECONDS=5
|
||||||
|
|
||||||
|
# =============================================================================
|
||||||
|
# CORS Settings
|
||||||
|
# =============================================================================
|
||||||
|
# JSON array of origins allowed by the FastAPI CORSMiddleware. Defaults match
|
||||||
|
# the previously hardcoded list: localhost, 127.0.0.1:8000 and api.honcho.dev.
|
||||||
|
# CORS_ORIGINS=["http://localhost","http://127.0.0.1:8000","https://api.honcho.dev"]
|
||||||
|
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
# Vector Store Settings
|
# Vector Store Settings
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
|
|
|
||||||
|
|
@ -1305,6 +1305,13 @@ class AppSettings(HonchoSettings):
|
||||||
LANGFUSE_HOST: str | None = None
|
LANGFUSE_HOST: str | None = None
|
||||||
LANGFUSE_PUBLIC_KEY: str | None = None
|
LANGFUSE_PUBLIC_KEY: str | None = None
|
||||||
|
|
||||||
|
# Origins allowed by the FastAPI CORSMiddleware
|
||||||
|
CORS_ORIGINS: list[str] = [
|
||||||
|
"http://localhost",
|
||||||
|
"http://127.0.0.1:8000",
|
||||||
|
"https://api.honcho.dev",
|
||||||
|
]
|
||||||
|
|
||||||
COLLECT_METRICS_LOCAL: bool = False
|
COLLECT_METRICS_LOCAL: bool = False
|
||||||
LOCAL_METRICS_FILE: str = "metrics.jsonl"
|
LOCAL_METRICS_FILE: str = "metrics.jsonl"
|
||||||
REASONING_TRACES_FILE: str | None = None # Path to JSONL file for reasoning traces
|
REASONING_TRACES_FILE: str | None = None # Path to JSONL file for reasoning traces
|
||||||
|
|
|
||||||
|
|
@ -183,15 +183,9 @@ app = FastAPI(
|
||||||
},
|
},
|
||||||
)
|
)
|
||||||
|
|
||||||
origins = [
|
|
||||||
"http://localhost",
|
|
||||||
"http://127.0.0.1:8000",
|
|
||||||
"https://api.honcho.dev",
|
|
||||||
]
|
|
||||||
|
|
||||||
app.add_middleware(
|
app.add_middleware(
|
||||||
CORSMiddleware,
|
CORSMiddleware,
|
||||||
allow_origins=origins,
|
allow_origins=settings.CORS_ORIGINS,
|
||||||
allow_credentials=True,
|
allow_credentials=True,
|
||||||
allow_methods=["*"],
|
allow_methods=["*"],
|
||||||
allow_headers=["*"],
|
allow_headers=["*"],
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue