mailship/.env.template
Agent fdc4579aa7 fix: scope CORS to browser routes only, require CORS_ORIGIN (fail closed)
The server was setting Access-Control-Allow-Origin: * on every route,
including the unauthenticated GET /subscription/email which returns the
subscriber's email address. Any website could query known pubkeys and
harvest emails.

Changes:
- src/env.ts: require CORS_ORIGIN env var (fail closed, no wildcard)
- src/server.ts: scope CORS middleware to browser-facing routes only,
  skip /notify (server-to-server), add Vary: Origin header, import
  CORS_ORIGIN from env instead of defaulting to '*'
- .env.template: document new CORS_ORIGIN variable
- test/cors.test.sh: verify CORS on browser routes, no CORS on
  server-to-server routes, Vary: Origin presence
2026-09-10 11:29:18 -04:00

22 lines
811 B
Text

MAILSHIP_SECRET=
MAILSHIP_NAME=Flotilla
MAILSHIP_URL=http://localhost:4738
BASE_URL=http://localhost:4738
# Branding used in email templates. EVENT_VIEWER_URL is the base URL of the
# app you link events into (Flotilla by default, or anything handling the same
# /spaces/<relay>/<group> and /<nevent> URL shapes).
EVENT_VIEWER_URL=https://app.flotilla.social
BRAND_NAME=Flotilla
BRAND_ACCENT=#7161FF
BRAND_LOGO=
INDEXER_RELAYS=purplepag.es,relay.damus.io,relay.nostr.band
DEFAULT_RELAYS=relay.damus.io,nos.lol
SEARCH_RELAYS=relay.nostr.band
# CORS_ORIGIN must be set to the exact origin your browser client runs on
# (e.g. https://app.example.com). There is no wildcard fallback — the server
# will refuse to start without it.
CORS_ORIGIN=
POSTMARK_API_KEY=
POSTMARK_SENDER_ADDRESS=
PORT=4738
DATA_DIR=./data