@@ -256,9 +256,8 @@ var msftAllowedOrigins = [ 'https://portal.azure.com', 'https://ms.portal.azure.
256256var loginEndpoint = environment ().authentication .loginEndpoint
257257var loginEndpointFixed = lastIndexOf (loginEndpoint , '/' ) == length (loginEndpoint ) - 1 ? substring (loginEndpoint , 0 , length (loginEndpoint ) - 1 ) : loginEndpoint
258258var allMsftAllowedOrigins = !(empty (clientAppId )) ? union (msftAllowedOrigins , [ loginEndpointFixed ]) : msftAllowedOrigins
259- var allowedOrigins = union (split (allowedOrigin , ';' ), allMsftAllowedOrigins )
260- // Filter out any empty origin strings and remove any duplicate origins
261- var allowedOriginsEnv = join (reduce (filter (allowedOrigins , o => length (trim (o )) > 0 ), [], (cur , next ) => union (cur , [next ])), ';' )
259+ // Combine custom origins with Microsoft origins, remove any empty origin strings and remove any duplicate origins
260+ var allowedOrigins = reduce (filter (union (split (allowedOrigin , ';' ), allMsftAllowedOrigins ), o => length (trim (o )) > 0 ), [], (cur , next ) => union (cur , [next ]))
262261
263262// Organize resources in a resource group
264263resource resourceGroup 'Microsoft.Resources/resourceGroups@2021-04-01' = {
@@ -393,7 +392,7 @@ var appEnvVariables = {
393392 AZURE_AUTH_TENANT_ID : tenantIdForAuth
394393 AZURE_AUTHENTICATION_ISSUER_URI : authenticationIssuerUri
395394 // CORS support, for frontends on other hosts
396- ALLOWED_ORIGIN : allowedOriginsEnv
395+ ALLOWED_ORIGIN : join ( allowedOrigins , ';' )
397396 USE_VECTORS : useVectors
398397 USE_GPT4V : useGPT4V
399398 USE_USER_UPLOAD : useUserUpload
0 commit comments