Skip to content

fix(api): drop the localhost default for WEB_ORIGIN - #58

Open
voidash wants to merge 1 commit into
mainfrom
fix/web-origin-optional
Open

voidash wants to merge 1 commit into
mainfrom
fix/web-origin-optional

Conversation

@voidash

@voidash voidash commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Production served access-control-allow-origin: http://localhost:5173 because WEB_ORIGIN defaulted to the dev origin. That same value is also on the CSRF origin allowlist and the post-login redirect allowlist, so in production a page on a visitor's own localhost:5173 got credentialed CORS, passed the CSRF guard, and was an accepted redirect target.

  • WEB_ORIGIN is optional with no default.
  • Unset: no CORS headers; only the request's own origin passes assertSameOrigin; redirects allow only the API origin.
  • Dev is unchanged: .env.example and vitest.config.mts already set it explicitly.

Verified: typecheck, biome, full vitest suite (155 tests) pass. New tests cover no default in parseEnv and redirects with no frontend origin.

After merge, redeploy on Dokploy; no env change needed (WEB_ORIGIN stays unset).

Production fell back to http://localhost:5173, which then received
credentialed CORS, passed the CSRF origin guard and was an accepted
post-login redirect target. Unset now means same-origin only.

Signed-off-by: ashish <ashish.thapa477@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant