Skip to content

BA-009 — Configure secure CORS from validated origins #577

Description

@MaryammAli
  • Type: Security
  • Affected area: src/main.ts, configuration
  • BackendAcademy
  • Summary: A permissive or absent CORS policy can expose authenticated APIs to unintended browser origins.
  • Acceptance criteria: Production requires an explicit allow-list; credentials behavior is intentional; preflight tests cover allowed and denied origins.

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions