fix: Sync platform CORS from App Config; contact consumer onboarding - #148
Conversation
Encode platform CORS origins in bicep so redeploys keep marketing contact forms working, and add the dual allowlist checklist plus sync:skills wiring. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
patoperpetua has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Warning Review limit reachedNext included review available in 8 minutes. View limit detailsLimit details: You’ve used all 3 included reviews currently available. Your 42 included PR review attempts over the past 7 days set your current allowance at 3 reviews per hour. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (12)
Comment |
|
Skills companion MR (source of truth is GitLab; GitHub is a read-only mirror): https://gitlab.com/singleton-sd/ai-plattform/skills/-/merge_requests/13 — skill path |
Record dual-CORS, Forward Email domain 500s, hostname/TLS sequence, and handoff pitfalls so future agents do not stop at live ops without a PR. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Added |
There was a problem hiding this comment.
patoperpetua has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Derive exact CORS origins from app:email:origins (non-glob) and profilesByHost keys via pnpm cors:sync; run on Deploy API. Drop the hardcoded bicep list so App Config stays the single source of truth. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Follow-up: platform CORS is now derived from App Config (not hardcoded in bicep).
|
There was a problem hiding this comment.
patoperpetua has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Summary
app:email:originshosts +profilesByHostkeys) viapnpm cors:sync/scripts/sync-function-cors-from-appconfig.sh; Deploy API runs it after seed.siteConfig.corsfrominfra/function-app.bicepso App Config stays the single source of truth (globs still apply at the function layer).postkit-contact-consumerintopnpm sync:skills(skills MR: https://gitlab.com/singleton-sd/ai-plattform/skills/-/merge_requests/13).mail.inkads.poc.singletonsd.comon Forward Email (provider 400 → HTTP 500).Closes #146
Test plan
node --test scripts/platform-cors-origins.test.mjspnpm cors:sync/ live App Config → Function App CORS matches profile hosts + localhostOPTIONS /contactOrigin InkAds → ACAOPOST /contact→ 202pnpm sync:skillsafter mirror updates