Rules Hub
Coding Rules Library
← Back to all rules
Rule priority, scope & exceptions
Use this to align rules with the senior-level structure (P0/P1/P2, scope, exceptions/tradeoffs).
backend ruleP1stack specificStack: node
corsexpresshttpcorrectness
Return CORS headers on both the OPTIONS preflight and the actual request
Apply CORS handling to both the preflight (OPTIONS) and the real GET/POST handler; browsers block the response otherwise.
PR: hegnar-web · org-mining-hist-2026-06Created: Jun 19, 2026
Bad example
Old codetypescript
| 1 | router.options('/data', cors(options)); |
| 2 | router.get('/data', handler); // missing CORS on the GET |
Explanation (EN)
Objašnjenje (HR)
Good example
New codetypescript
| 1 | router.options('/data', cors(options)); |
| 2 | router.get('/data', cors(options), handler); |
Explanation (EN)
Objašnjenje (HR)