Skip to content

BA-009 — Configure secure CORS from validated origins #577

Description

@MaryammAli
  • Type: Security
  • Affected area: src/main.ts, configuration
  • BackendAcademy
  • Summary: A permissive or absent CORS policy can expose authenticated APIs to unintended browser origins.
  • Acceptance criteria: Production requires an explicit allow-list; credentials behavior is intentional; preflight tests cover allowed and denied origins.

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions