18 lines
995 B
Markdown
18 lines
995 B
Markdown
# Spec: fix-dashboard-cors-origin
|
|||
|
|
|
||
|
|
## Problem
|
||
|
|
`automaton/dashboard/ui/app.py:40-44` sets `Access-Control-Allow-Origin: *` on all responses, including POST and PUT endpoints. Any website open in the user's browser can send cross-origin requests to `localhost:8080`, allowing silent modification of task reviews and config.
|
||
|
|
|
||
|
|
## Fix
|
||
|
|
Remove the wildcard CORS origin. The dashboard is a local single-origin app — CORS headers are unnecessary. Either:
|
||
|
|
1. Remove `CORS_HEADERS` entirely and stop sending them, OR
|
||
|
|
2. Set `Access-Control-Allow-Origin` to `http://localhost:{port}` only
|
||
|
|
|
||
|
|
Option 1 is simpler and safer. The dashboard serves both the HTML and the API from the same origin, so CORS is not needed.
|
||
|
|
|
||
|
|
## Acceptance Criteria
|
||
|
|
- No `Access-Control-Allow-Origin: *` header in responses
|
||
|
|
- Cross-origin requests from other websites are blocked by the browser
|
||
|
|
- Same-origin dashboard HTML can still fetch the API (no CORS needed)
|
||
|
|
- Existing CORS tests in `test_app.py` updated to reflect the change
|