expressjs/cors

CORS requests with credentials should forbid `*`

オープン

#333 opened on 2024/10/19

 (4 件のコメント) (0 件のリアクション) (0 人の担当者)JavaScript (476 件のフォーク)batch import
3.xbughelp wanted

Repository metrics

Stars
 (5,897 個のスター)
PR merge metrics
 (PR metrics pending)

説明

The standard forbids using * in the Access-Control-Allow-Origin, Access-Control-Expose-Headers, Access-Control-Allow-Methods, or Access-Control-Allow-Headers response header, if the Access-Control-Allow-Credentials request header is set to true.

https://fetch.spec.whatwg.org/#cors-protocol-and-credentials

https://fetch.spec.whatwg.org/#http-new-header-syntax

Right now, this module allows it. In fact, it does it by default if the credentials option is set to true.

Instead, it could either:

  • Throw an error
  • Not set CORS response headers, i.e. rejecting the CORS request
  • Use the Origin request header, if specified. The Vary: Origin response header would need to be set too then.

コントリビューターガイド