mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-04-26 01:35:54 +03:00
[PR #1469] [MERGED] CORS fixes #2963
Labels
No labels
SSO
Third party
better for forum
bug
bug
documentation
duplicate
enhancement
future Vault
future Vault
future Vault
good first issue
help wanted
low priority
notes
pull-request
question
troubleshooting
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vaultwarden#2963
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/dani-garcia/vaultwarden/pull/1469
Author: @jjlin
Created: 3/7/2021
Status: ✅ Merged
Merged: 3/15/2021
Merged by: @dani-garcia
Base:
master← Head:cors📝 Commits (2)
7d0e234CORS fixesd93c344Merge branch 'master' into cors📊 Changes
1 file changed (+14 additions, -8 deletions)
View changed files
📝
src/util.rs(+14 -8)📄 Description
The Safari extension apparently now uses the origin
file://and expectsthat to be returned (see bitwarden/browser#1311, bitwarden/server#800).
The
Access-Control-Allow-Originheader was reflecting the value of theOriginheader without checking whether the origin was actually allowed.This effectively allows any origin to interact with the server, which
defeats the purpose of CORS.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.