Skip to main content

cors-cookie-auth

Cookie-based auth from a different origin (e.g. frontend on 3001, backend on 3000) requires Access-Control-Allow-Credentials true and a specific Access-Control-Allow-Origin (not *). If framework middleware does not apply to API routes, add CORS headers in the route handler. Use when debugging cross-origin cookie/session issues.

来源信息

仓库
pmarashian/cursor-agent-skills
最近来源活动
2026年2月13日 19:51
检测到的 SKILL.md 语言
英语
星标
2
分支
1

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
cors-cookie-auth
description
Cookie-based auth from a different origin (e.g. frontend on 3001, backend on 3000) requires Access-Control-Allow-Credentials true and a specific Access-Control-Allow-Origin (not *). If framework middleware does not apply to API routes, add CORS headers in the route handler. Use when debugging cross-origin cookie/session issues.
# CORS and Cookie-Based Auth (Cross-Origin) For **cookie-based auth** when the frontend is on a different origin than the backend (e.g. frontend port 3001, backend port 3000): ## Backend Must Send - **`Access-Control-Allow-Credentials: true`** - **Specific `Access-Control-Allow-Origin`** (e.g. `http://localhost:3001`) — **not** `*`. With credentials, `*` is not allowed. ## If Middleware Doesn't Apply to API Routes - Framework middleware (e.g. Next.js middleware) may not apply to API route responses. - **Fallback**: Set CORS headers **in the API route handler** (or in a wrapper around the handler) so they appear on the response. ## Verify - Use `curl -v -H 'Origin: http://localhost:3001' http://localhost:3000/api/...` and confirm `Access-Control-*` headers are present in the response. ## Why This Matters Tasks have spent many steps editing middleware before finding that middleware was not affecting API responses; moving CORS and credentials into the route handler fixed the issue.
在 GitHub 查看