Skip to content

Conversation

@tkesgar
Copy link

@tkesgar tkesgar commented May 19, 2025

Currently, the plugin sends a set of default headers for Access-Control-Allowed-Headers and Access-Control-Expose-Headers:

image

We can actually set allowedHeaders and exposeHeaders to false to avoid sending the headers:

const app = new Elysia()
  .use(cors({
    allowedHeaders: false as any,
    exposeHeaders: false as any,
  }))

image

This PR updates the types so false is accepted as value for the options.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant