The server was setting Access-Control-Allow-Origin: * on every route, including the unauthenticated GET /subscription/email which returns the subscriber's email address. Any website could query known pubkeys and harvest emails. Changes: - src/env.ts: require CORS_ORIGIN env var (fail closed, no wildcard) - src/server.ts: scope CORS middleware to browser-facing routes only, skip /notify (server-to-server), add Vary: Origin header, import CORS_ORIGIN from env instead of defaulting to '*' - .env.template: document new CORS_ORIGIN variable - test/cors.test.sh: verify CORS on browser routes, no CORS on server-to-server routes, Vary: Origin presence
22 lines
811 B
Text
22 lines
811 B
Text
MAILSHIP_SECRET=
|
|
MAILSHIP_NAME=Flotilla
|
|
MAILSHIP_URL=http://localhost:4738
|
|
BASE_URL=http://localhost:4738
|
|
# Branding used in email templates. EVENT_VIEWER_URL is the base URL of the
|
|
# app you link events into (Flotilla by default, or anything handling the same
|
|
# /spaces/<relay>/<group> and /<nevent> URL shapes).
|
|
EVENT_VIEWER_URL=https://app.flotilla.social
|
|
BRAND_NAME=Flotilla
|
|
BRAND_ACCENT=#7161FF
|
|
BRAND_LOGO=
|
|
INDEXER_RELAYS=purplepag.es,relay.damus.io,relay.nostr.band
|
|
DEFAULT_RELAYS=relay.damus.io,nos.lol
|
|
SEARCH_RELAYS=relay.nostr.band
|
|
# CORS_ORIGIN must be set to the exact origin your browser client runs on
|
|
# (e.g. https://app.example.com). There is no wildcard fallback — the server
|
|
# will refuse to start without it.
|
|
CORS_ORIGIN=
|
|
POSTMARK_API_KEY=
|
|
POSTMARK_SENDER_ADDRESS=
|
|
PORT=4738
|
|
DATA_DIR=./data
|