<?php

$origins = array_values(array_filter(array_map(
    'trim',
    explode(',', (string) env('CORS_ALLOWED_ORIGINS', ''))
)));

$originPatterns = array_values(array_filter(array_map(
    'trim',
    explode(',', (string) env('CORS_ALLOWED_ORIGIN_PATTERNS', ''))
)));

// Flutter web / browser dev servers commonly use random localhost ports.
// These patterns only match loopback origins, so they are safe to keep enabled.
$originPatterns = array_values(array_unique(array_merge($originPatterns, [
    '#^https?://localhost(:\d+)?$#',
    '#^https?://127\.0\.0\.1(:\d+)?$#',
])));

return [
    'paths' => ['api/*', 'sanctum/csrf-cookie'],

    'allowed_methods' => ['GET', 'POST', 'PUT', 'PATCH', 'DELETE', 'OPTIONS'],

    // Empty env => deny browser cross-origin (mobile native apps are unaffected).
    // Set CORS_ALLOWED_ORIGINS=https://app.example.com
    // Optional: CORS_ALLOWED_ORIGIN_PATTERNS=#^https://.*\.example\.com$#
    'allowed_origins' => $origins,

    'allowed_origins_patterns' => $originPatterns,

    'allowed_headers' => ['*'],

    'exposed_headers' => [],

    'max_age' => 0,

    'supports_credentials' => false,
];
