Skip to content

CORS fix in PR #1 hardcodes an all-or-nothing origin list with no dynamic/wildcard-subdomain support #49

Description

@ndii-dev

The post-fix cors({ origin: process.env.CORS_ORIGIN?.split(",") ?? false }) requires every allowed origin to be listed verbatim in one env var — this doesn't scale to, e.g., preview-deployment subdomains (*.vercel.app style) without either a wildcard hole or constant env-var churn on every deploy. Design a proper origin-validation function instead of a static split list.

Definition of done:

  • Origin validation supports pattern-based allowlisting (e.g. specific subdomain patterns) without falling back to an open wildcard
  • Still defaults closed (false) when unconfigured, preserving PR fix: require API key on wallet routes, default-deny CORS #1's fix
  • Covered by tests for both the exact-match and pattern-match cases

Before opening a PR for this issue, read CONTRIBUTING.md.

This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:

  • Root cause / design-decision rationale in your own words — not a restatement of this issue
  • Every Definition of done bullet above addressed explicitly, with a one-line note on how
  • Evidence the code actually runs: pasted test/build output, a screen recording or before/after screenshots for UI changes, or real (non-mocked) logs for network/contract-facing work
  • New or updated tests included and shown passing (paste the output)
  • Any adjacent/related behavior this issue calls out re-verified, not assumed unaffected

PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.

Metadata

Metadata

Assignees

No one assigned

    Labels

    GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions