diff --git a/api/_studio.js b/api/_studio.js index ac65548..67d5bb3 100644 --- a/api/_studio.js +++ b/api/_studio.js @@ -30,13 +30,17 @@ const ALLOWED_ORIGINS = [ 'http://127.0.0.1:3000', ]; +/** 이 프로젝트의 미리보기 배포 주소. 미리보기는 Vercel 로그인(배포 보호) 뒤에 있어 팀원만 연다. */ +const PREVIEW_ORIGIN = /^https:\/\/infinith-demo-[a-z0-9]+-o2odev-5530s-projects\.vercel\.app$/; +const isAllowedOrigin = (o) => ALLOWED_ORIGINS.includes(o) || PREVIEW_ORIGIN.test(o); + /** * CORS·메서드·출처를 확인한다. 통과하면 null, 아니면 이미 응답을 보낸 뒤 true 를 돌려준다. * @param {string[]} methods 허용 메서드 */ export function guard(req, res, methods) { const origin = req.headers.origin || ''; - const allowed = ALLOWED_ORIGINS.includes(origin); + const allowed = isAllowedOrigin(origin); if (allowed) { res.setHeader('Access-Control-Allow-Origin', origin); res.setHeader('Vary', 'Origin'); @@ -53,7 +57,8 @@ export function guard(req, res, methods) { } // 같은 출처 GET 은 브라우저가 Origin 을 붙이지 않을 수 있어 Referer 로도 확인한다. const referer = req.headers.referer || ''; - const sameSite = ALLOWED_ORIGINS.some((o) => referer.startsWith(o + '/')); + const refOrigin = (referer.match(/^https?:\/\/[^/]+/) || [''])[0]; + const sameSite = isAllowedOrigin(refOrigin); if (!allowed && !sameSite) { res.status(403).json({ ok: false, error: 'forbidden origin' }); return true;