Skip to content

[LOW] Permissive default CORS #227

@ibuyspy

Description

@ibuyspy

\�pp.use(cors())\ at \�pps/api/src/index.ts:35\ allows all origins.

Fix: Use explicit origin allowlist per environment; restrict methods/headers.
Source: Security audit

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity-related finding

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions