Skip to content

CORS Configuration

CORS Configuration sits at the heart of security in single-spa. This guide walks through the concept step by step, with examples, a cheatsheet, and common mistakes to avoid.

CORS Configuration Overview

CORS Configuration lets you structure single-spa work so it stays readable, testable, and easy to scale. Instead of ad-hoc code, you follow a clear pattern that other developers can recognise immediately.

The key is to keep cors configuration focused and predictable. Start from the minimal example here, then layer in only the complexity your feature actually needs.

import { registerApplication, start } from 'single-spa';

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});

start();

single-spa orchestrates multiple framework apps on one page through a root config.

CORS Configuration Example

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});
start();
  • Start from a minimal CORS Configuration example and grow it only as needed.
  • Keep configuration explicit so CORS Configuration behaves the same in every environment.
  • Name things clearly so teammates understand your CORS Configuration at a glance.
  • Add tests around CORS Configuration early to lock in expected behaviour.

Single-SPA Cheatsheet

Core single-spa APIs related to cors configuration.

API Example Purpose
registerApplication registerApplication({ name, app, activeWhen }) Register a micro frontend
activeWhen activeWhen: ['/checkout'] Route ownership
start start() Begin routing
bootstrap export async function bootstrap() One-time setup
mount export async function mount(props) Render the app
unmount export async function unmount(props) Clean up the app
import map systemjs-importmap Locate app bundles

How CORS Configuration Works in Single-SPA

CORS Configuration is part of how single-spa lets multiple applications — even in different frameworks — coexist on one page. A root config registers each app and controls when it is active.

single-spa orchestrates multiple framework apps on one page through a root config.

  • A root config registers apps and calls start().
  • Each app exports bootstrap, mount, and unmount lifecycles.
  • activeWhen decides which routes each app owns.
  • Import maps resolve each app's bundle at runtime.

Practical Guidance for CORS Configuration

For reliable micro frontends, cors configuration should isolate failures and keep shared state minimal. Let each team own its app end to end while agreeing on a few shared contracts.

Concern Recommendation
Isolation One app's crash should not break others
Shared state Prefer shared utility modules over globals
Routing Keep activeWhen rules explicit and non-overlapping
Deployment Release via import-map updates per app

Common Mistakes

  • Skipping error handling and edge cases when wiring up cors configuration.
  • Leaving cors configuration untested, so regressions slip into production.
  • Over-engineering cors configuration before you actually need the extra flexibility.
  • Ignoring documentation, which makes cors configuration hard for the next developer to change.

Key Takeaways

  • CORS Configuration is a core part of working effectively with single-spa.
  • Start small and keep cors configuration focused on a single responsibility.
  • Apply consistent patterns so cors configuration scales across your project.
  • Test and document cors configuration to keep it maintainable over time.

Pro Tip

When you get stuck on cors configuration, reduce it to the smallest reproducible example first — most single-spa issues become obvious once the noise is gone.