Summary
Add Cross-Origin Resource Sharing (CORS) support to Register Your Data so that
the new IATI Dashboard frontend (a browser-based SPA) can make authenticated calls to this API.
Background / Motivation
The new IATI Dashboard frontend is going to be a single-page application. It will authenticate users via SSO (Authorization Code flow with PKCE) and call Register Your Data with a Bearer token. Because the SPA runs in the browser on a different origin than the API, the browser's Same-Origin Policy will block the calls unless the API explicitly permits that origin via CORS.
Requirements
- Configure CORS on the FastAPI app using the built-in
CORSMiddleware
(fastapi.middleware.cors.CORSMiddleware).
- The set of allowed origins should be config-driven, not hardcoded:
- sourced from application configuration (e.g. an environment variable/or a list in a file), with a sensible default - check if FastAPI has a best practice on this;
- extendable without a code change when new origins need access
- Response headers must permit:
- the
Authorization header (the SPA sends Authorization: Bearer <token> on every request);
- the HTTP methods used by the SPA (at minimum
GET, POST, OPTIONS).
- Preflight
OPTIONS requests must be answered successfully without requiring authentication, so that browser preflights do not receive a 401.
- Do not use
Access-Control-Allow-Origin: *; just fix to IATI Dashboard.
allow_credentials should be False unless the API moves to cookie-based auth (current SPA integration uses Bearer tokens).
Acceptance Criteria
Out of Scope
- Authentication/token validation changes — the SPA will use the same SSO tokens the API already accepts.
Summary
Add Cross-Origin Resource Sharing (CORS) support to Register Your Data so that
the new IATI Dashboard frontend (a browser-based SPA) can make authenticated calls to this API.
Background / Motivation
The new IATI Dashboard frontend is going to be a single-page application. It will authenticate users via SSO (Authorization Code flow with PKCE) and call Register Your Data with a Bearer token. Because the SPA runs in the browser on a different origin than the API, the browser's Same-Origin Policy will block the calls unless the API explicitly permits that origin via CORS.
Requirements
CORSMiddleware(
fastapi.middleware.cors.CORSMiddleware).Authorizationheader (the SPA sendsAuthorization: Bearer <token>on every request);GET,POST,OPTIONS).OPTIONSrequests must be answered successfully without requiring authentication, so that browser preflights do not receive a 401.Access-Control-Allow-Origin: *; just fix to IATI Dashboard.allow_credentialsshould beFalseunless the API moves to cookie-based auth (current SPA integration uses Bearer tokens).Acceptance Criteria
OPTIONS) requests return a 2xx without credentials and include the expectedAccess-Control-Allow-*headers.Access-Control-Allow-Originheader is not emitted for them).Out of Scope