KamoCRM

Cache CORS preflights for two hours, not 100 seconds

FixKlusterServices
Shipped
20 ஆகஸ்ட், 2026 அன்று 2:55 PM UTC
Author
Kamo
Commit
088c612

`accessControlMaxAge: 100` meant browsers re-ran the preflight roughly once per visit, so every page load on the marketing site paid two extra OPTIONS round-trips — to api. for the chat bootstrap and to analytics. for the beacon — before the requests it actually wanted. Measured with Chrome against the live site. It was also overriding APIService, which sets `setMaxAge(3600)` in its own CORS config and was being silently ignored by the middleware in front of it. 7200 is Chrome's ceiling; larger values are clamped to it. This cannot loosen access — the allow-lists alongside it are what grant that — it only stops the browser re-asking a question it already holds the answer to.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing