# koa2-cors

> cors middleware for koa2

Latest version **2.0.6** (published 2018-07-17) · MIT license · 0 weekly downloads

## Install

```sh
npm install koa2-cors
pnpm add koa2-cors
yarn add koa2-cors
bun add koa2-cors
```

## Health

**Score 23/100 (F)** — status: abandoned.

Positive: has types package; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 2.0.6 |
| Published | 2018-07-17 |
| First published | 2016-12-29 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | separate (@types/koa2-cors) |
| Module format | CommonJS |
| Node | >= 7.6.0 |
| Dependencies | 0 |
| Unpacked size | 11 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 237 |
| Author | zad |
| Maintainers | zadzbw |
| Keywords | koa2, cors, middleware |

## Links

- npm: https://www.npmjs.com/package/koa2-cors
- Repository: https://github.com/zadzbw/koa2-cors
- Homepage: https://github.com/zadzbw/koa2-cors#readme
- Issues: https://github.com/zadzbw/koa2-cors/issues
- npm.io page: https://npm.io/package/koa2-cors

## Alternatives

- [@sindresorhus/slugify](https://npm.io/package/@sindresorhus/slugify.md) — 3.7M weekly downloads
- [solid-js](https://npm.io/package/solid-js.md) — 2.7M weekly downloads
- [expo-glass-effect](https://npm.io/package/expo-glass-effect.md) — 2.5M weekly downloads
- [nanoassert](https://npm.io/package/nanoassert.md) — 780.8K weekly downloads
- [@ffmpeg/ffmpeg](https://npm.io/package/@ffmpeg/ffmpeg.md) — 529.5K weekly downloads

## Recent versions

- 2.0.6 (latest) — 2018-07-17
- 2.0.5 — 2017-11-15
- 2.0.4 — 2017-11-08
- 2.0.3 — 2017-01-19
- 2.0.2 — 2016-12-29

## README

# koa2-cors

## install

> it requires node v7.6.0 or higher now

```bash
npm install --save koa2-cors
```

## Usage

```js
var Koa = require('koa');
var cors = require('koa2-cors');

var app = new Koa();
app.use(cors());
```

## Options

### origin

Configures the **Access-Control-Allow-Origin** CORS header. expects a string. Can also be set to a function, which takes the `ctx` as the first parameter.

### exposeHeaders

Configures the **Access-Control-Expose-Headers** CORS header. Expects a comma-delimited array.

### maxAge

Configures the **Access-Control-Max-Age** CORS header. Expects a
Number.

### credentials

Configures the **Access-Control-Allow-Credentials** CORS header. Expects a Boolean.

### allowMethods

Configures the **Access-Control-Allow-Methods** CORS header. Expects a comma-delimited array , If not specified, default allowMethods is `['GET', 'PUT', 'POST', 'PATCH', 'DELETE', 'HEAD', 'OPTIONS']`.

### allowHeaders
Configures the **Access-Control-Allow-Headers** CORS header. Expects a comma-delimited array . If not specified, defaults to reflecting the headers specified in the request's **Access-Control-Request-Headers** header.

```js
var Koa = require('koa');
var cors = require('koa2-cors');

var app = new Koa();
app.use(cors({
  origin: function(ctx) {
    if (ctx.url === '/test') {
      return false;
    }
    return '*';
  },
  exposeHeaders: ['WWW-Authenticate', 'Server-Authorization'],
  maxAge: 5,
  credentials: true,
  allowMethods: ['GET', 'POST', 'DELETE'],
  allowHeaders: ['Content-Type', 'Authorization', 'Accept'],
}));
...
```

[More details about CORS](https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS).

## License

[MIT License](http://www.opensource.org/licenses/mit-license.php)

---
_Source: https://npm.io/package/koa2-cors · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
