Skip to content

fix(security): CORS reflects any Origin and Allow-Credentials true - #2873

Open
SAUMILDHANKAR wants to merge 1 commit into
developfrom
saumildhankar-cors-origin-credentials
Open

fix(security): CORS reflects any Origin and Allow-Credentials true#2873
SAUMILDHANKAR wants to merge 1 commit into
developfrom
saumildhankar-cors-origin-credentials

Conversation

@SAUMILDHANKAR

@SAUMILDHANKAR SAUMILDHANKAR commented Aug 31, 2026

Copy link
Copy Markdown
Member
  • .env would need adding allowlist CORS_ALLOWED_ORIGINS=https://la.foodoasis.net,https://foodoasis.la,https://hi.foodoasis.net,https://sb.foodoasis.net,https://mck.foodoasis.net
  • Number 6 on the list

@junjun107
junjun107 self-requested a review September 1, 2026 02:32
@SAUMILDHANKAR

Copy link
Copy Markdown
Member Author

Hi @junjun107 i want to update env with
CORS_ALLOWED_ORIGINS=https://devla.foodoasis.net,http://localhost:3000,https://la.foodoasis.net,https://foodoasis.la,https://sb.foodoasis.net,https://mck.foodoasis.net
So it addresses dev env, localhost and Bryan's Hawaii suggestion. Hope it is fine. Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants