fix(database,api): add 6 missing table migrations and fix CORS health checks

Database: 6 models in the Prisma schema had no CREATE TABLE migration:
cron_schedules, workspace_llm_settings, quality_gates, task_rejections,
token_budgets, llm_usage_logs. Same root cause as the federation tables.

CORS: Health check requests (Docker, load balancers) don't send Origin
headers. The CORS config was rejecting these in production, causing
/health to return 500 and Docker to mark the container as unhealthy.
Requests without Origin headers are not cross-origin per the CORS spec
and should be allowed through.

Co-Authored-By: Claude Opus 4.6 <[email protected]>
This commit is contained in:
2026-02-15 01:49:13 -06:00
co-authored by Claude Opus 4.6
parent dfe89b7a3b
commit 8ce6843af2
2 changed files with 165 additions and 7 deletions
+3 -7
View File
@@ -66,14 +66,10 @@ async function bootstrap() {
origin: string | undefined,
callback: (err: Error | null, allow?: boolean) => void
): void => {
// SECURITY: In production, reject requests with no Origin header.
// In development, allow no-origin requests (Postman, curl, mobile apps).
// Allow requests with no Origin header (health checks, server-to-server,
// load balancer probes). These are not cross-origin requests per the CORS spec.
if (!origin) {
if (isDevelopment) {
callback(null, true);
} else {
callback(new Error("CORS: Origin header is required"));
}
callback(null, true);
return;
}