Scope CORS to browser routes only, fail closed on CORS_ORIGIN #4
Loading…
Reference in a new issue
No description provided.
Delete branch "mailship-32x-cors-is-not-production-safe-wildcard-ori-52b"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
mailship-32x
The server was setting
Access-Control-Allow-Origin: *on every route viaprocess.env.CORS_ORIGIN ?? '*', including the unauthenticatedGET /subscription/email?pubkey=...which returns the subscriber's email address. Any website could query known pubkeys and harvest emails.Changes:
src/env.ts—CORS_ORIGINis now a required env var (fail closed). The server refuses to start without it. Also exported for use in server middleware.src/server.ts— replaced the blanket CORS middleware with a scopedcorsMiddlewarethat skips server-to-server routes (/notify), readsCORS_ORIGINfrom env (no?? '*'fallback), and addsVary: Origin..env.template— documented the new required variable.test/cors.test.sh— integration test that verifies: configured origin on browser routes,Vary: Originpresence, no CORS headers on/notify, and correct preflight responses.How to test: Set
CORS_ORIGIN=https://your-app.comin the environment (or.env). Without it, the server will exit withError: CORS_ORIGIN is not defined.Runbash test/cors.test.shfor automated verification.