4 ms·
From my experience, when you want to have 12 factor apps and just build your Frontend/backend once, and don’t want to leak absolute urls in the Frontend code, y
by weitzj 5y ago
From my experience, when you want to have 12 factor apps and just build your Frontend/backend once, and don’t want to leak absolute urls in the Frontend code, you are better of with relative URL’s anyways, i.e. /api for your api, and let a reverse proxy do the proper mapping to your services.
Then of course you don’t need CORS
- Cthulhu_ 5y agoThat's what I tend to stick to, CORS is a headache and very easy to do wrong and you shouldn't do it unless you make an open API that can be directly integrated into other websites - which is probably a bad idea. For most if not all use cases, you can set up a proxy in your front-end's web server so that it doesn't need CORS.
- youngtaff 5y agoThis!
- 9dev 5y agoThat's one strategy. Having something like `API_URL=https://api.foo.bar/v1 https://api.foo.bar/v1` works equally well for 12 factor apps, and gives you the added benefit of transparently pointing to test hosts or staging versions running elsewhere.
- weitzj 5y agoYeah. I would have this env var inside my reverse proxy to have it 12-factor app compatible. And I guess your solution as well? And you have some templating mechanism to replace the absolute variable on the fly? I would use a mix of your solution, i.e. allow the Java script client to be configured with either absolute or relative urls in case one needs to point the client elsewhere + reverse proxy