Skip to content

FOUR-33655: Reject OPTIONS requests to login - #9087

Open
eiresendez wants to merge 1 commit into
developfrom
defect/FOUR-33655
Open

eiresendez wants to merge 1 commit into
developfrom
defect/FOUR-33655

Conversation

@eiresendez

Copy link
Copy Markdown
Contributor

Issue & Reproduction Steps

Laravel automatically responds to OPTIONS /login with HTTP 200 and an Allow header. This behavior was reported as an HTTP OPTIONS exposure on the login endpoint.

Solution

  • Add an explicit OPTIONS /login route that returns HTTP 405 with an empty response body.
  • Preserve GET, HEAD, and POST as the allowed login methods.
  • Add regression coverage for the expected response status, header, and body.

How to Test

  • Run Tests\Feature\RouteTest::testLoginDoesNotAllowOptions.
  • Verify that OPTIONS /login returns HTTP 405 with Allow: GET, HEAD, POST and an empty body.
  • Verify that the normal login page and login submission continue to work.
  • Verify that API CORS preflight requests continue to work.

PHP syntax checks passed for the changed route and test files. The automated feature test was not run.

Related Tickets & Packages

ci:deploy

@eiresendez eiresendez self-assigned this Oct 5, 2026
@decisions-sonarqube

Copy link
Copy Markdown

@vladyrichter

Copy link
Copy Markdown

QA server K8S was successfully deployed https://tenant-1.ci-edb8662af6.engk8s.processmaker.net

@CarliPinell

Copy link
Copy Markdown
Contributor

The code looks good. No observations.

@CarliPinell
CarliPinell self-requested a review October 6, 2026 14:22

@CarliPinell CarliPinell left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No observations were found

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants