You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The post-fix cors({ origin: process.env.CORS_ORIGIN?.split(",") ?? false }) requires every allowed origin to be listed verbatim in one env var — this doesn't scale to, e.g., preview-deployment subdomains (*.vercel.app style) without either a wildcard hole or constant env-var churn on every deploy. Design a proper origin-validation function instead of a static split list.
Definition of done:
Origin validation supports pattern-based allowlisting (e.g. specific subdomain patterns) without falling back to an open wildcard
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
Root cause / design-decision rationale in your own words — not a restatement of this issue
Every Definition of done bullet above addressed explicitly, with a one-line note on how
Evidence the code actually runs: pasted test/build output, a screen recording or before/after screenshots for UI changes, or real (non-mocked) logs for network/contract-facing work
New or updated tests included and shown passing (paste the output)
Any adjacent/related behavior this issue calls out re-verified, not assumed unaffected
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.
The post-fix cors({ origin: process.env.CORS_ORIGIN?.split(",") ?? false }) requires every allowed origin to be listed verbatim in one env var — this doesn't scale to, e.g., preview-deployment subdomains (*.vercel.app style) without either a wildcard hole or constant env-var churn on every deploy. Design a proper origin-validation function instead of a static split list.
Definition of done:
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.