symfony-boilerplate icon indicating copy to clipboard operation
symfony-boilerplate copied to clipboard

Fix - CORS allowing undesired origins

Open dsavina opened this issue 3 years ago • 0 comments

Regex mode allowed undesired domains to perform cross-origin requests, by simply satisfying the regex corresponding to the authorized origin. For instance, if the authorized origin (i.e. the web app) was https://my.website.com, cross-origin requests could be sent from https://my.website.com.mischievo.us, or even https://myawebsite.com.

dsavina avatar Jul 12 '22 10:07 dsavina