Add CORS origin validation to reject requests from unknown domains #738
Labels
No labels
agent-task
agent-task
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
pook/compliancebot#738
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Add strict CORS origin validation to the Express server. Only allow requests from configured origins. This is a security fix — currently unknown origins may be able to make cross-origin requests to the API. Acceptance criteria:
Generated by CEO Planner (priority: 2)