Skip to content

fix(security): make CORS opt-in#210

Open
elkozmon wants to merge 1 commit into
masterfrom
codex/harden-cors-auth-defaults
Open

fix(security): make CORS opt-in#210
elkozmon wants to merge 1 commit into
masterfrom
codex/harden-cors-auth-defaults

Conversation

@elkozmon

@elkozmon elkozmon commented Jun 10, 2026

Copy link
Copy Markdown
Owner

Summary

  • Make CORS opt-in for the default Play, Docker, and Snap configurations.
  • Add explicit Docker/Snap allowed-origin configuration docs.
  • Document the trust boundary for enabling cross-origin browser access.

Verification

  • bash -n build/docker/files/api/conf/zoonavigator.conf.sh
  • sh -n build/snap/local/bin/configure
  • /private/tmp/zn-docs-venv/bin/sphinx-build -W -b html docs /private/tmp/zoonavigator-docs-cors-split

@elkozmon elkozmon force-pushed the codex/harden-cors-auth-defaults branch from eb489f6 to 54334e4 Compare June 10, 2026 15:29
@elkozmon elkozmon changed the title fix(security): make CORS opt-in and harden auth parsing fix(security): make CORS opt-in Jun 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant