forked from 0xWheatyz/SPARC
Security: make CORS allowed-origins configurable via environment variable #272
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
api.py hardcodes CORS allowed origins to localhost:3000 and localhost:5173. The dashboard breaks when deployed behind any real domain because browser preflight requests are rejected.
Acceptance Criteria
References
Roadmap: P1 Security hardening -- CORS allow-origins are hardcoded.