diff --git a/api/server.js b/api/server.js index c3cb40c..98159e8 100644 --- a/api/server.js +++ b/api/server.js @@ -42,7 +42,15 @@ puppeteer.launch(puppeteerParams).then(browser => { server.use(morgan('tiny')) } - server.use(cors()) + server.use( + cors({ + origin(origin, callback) { + return origin === 'https://carbon.now.sh' || !origin + ? callback(null, true) + : callback(new Error('Not allowed by CORS')) + } + }) + ) server.use(compression())