MediumPro challengePythonJavaScriptTypeScript

CORS Preflight Check

Node.jsHTTPCORS

Given a CORS config and an incoming request, return whether it's allowed
and the response headers to send.

Config: { origins: string[] | '*', methods: string[], headers: string[] }.
Request: { origin, method, headers }.

Returns { allowed, responseHeaders }. If origin matches '*' or is in
origins, method is in methods, and every requested header is in
allowed headers (case-insensitive), it's allowed.

Sample tests

Test #1Header not allowed
Input: [{"headers":["authorization"],"methods":["GET"],"origins":["https://x.com"]},{"method":"GET","origin":"https://x.com","headers":["x-foo"]}]
Output: {"allowed":false,"responseHeaders":{}}
Test #2Specific origin echoed
Input: [{"headers":["authorization","content-type"],"methods":["GET","POST"],"origins":["https://api.com"]},{"method":"POST","origin":"https://api.com","headers":["Authorization","Content-Type"]}]
Output: {"allowed":true,"responseHeaders":{"Access-Control-Allow-Origin":"https://api.com","Access-Control-Allow-Headers":"authorization, content-type","Access-Control-Allow-Methods":"GET, POST"}}
Test #3Wildcard origin
Input: [{"headers":["content-type"],"methods":["GET"],"origins":"*"},{"method":"GET","origin":"https://x.com","headers":["Content-Type"]}]
Output: {"allowed":true,"responseHeaders":{"Access-Control-Allow-Origin":"*","Access-Control-Allow-Headers":"content-type","Access-Control-Allow-Methods":"GET"}}
Test #4Origin not allowed
Input: [{"headers":[],"methods":["POST"],"origins":["https://x.com"]},{"method":"POST","origin":"https://y.com","headers":[]}]
Output: {"allowed":false,"responseHeaders":{}}
Test #5Method not allowed
Input: [{"headers":[],"methods":["GET"],"origins":["https://x.com"]},{"method":"POST","origin":"https://x.com","headers":[]}]
Output: {"allowed":false,"responseHeaders":{}}