feat: implement CORS policy management with dynamic origin whitelisting - #1037
Open
menawar wants to merge 1 commit into
Open
feat: implement CORS policy management with dynamic origin whitelisting#1037menawar wants to merge 1 commit into
menawar wants to merge 1 commit into
Conversation
Closes Smartdevs17#1000 - Export all CORS policy management symbols from backend/services/shared/index.ts so consumers can import them from the shared barrel - Integrate CORS middleware into backend/server.ts: * Apply CORS headers to every incoming request before routing * Short-circuit OPTIONS preflight with 204/403 response * Seed a default 'default' CORS policy from CORS_ALLOWED_ORIGIN env var * Add GET /cors/analytics endpoint * Add GET /cors/violations endpoint - Add comprehensive test suite (47 tests) covering: * Policy CRUD: upsertPolicy, getPolicy, getAllPolicies, deletePolicy * Origin matching: exact, wildcard subdomains, tenant scoping * processCorsRequest: allowed/blocked, credentials, exposed headers, OPTIONS preflight, preflight cache hit/miss, clearPreflightCache * Analytics counters: totalRequests, allowedRequests, blockedRequests, requestsByMethod, violationsByOrigin, violationsByTenant * getViolations filtering: by tenantId, origin, limit, since * createCorsMiddleware Express-style factory * resetAnalytics * Integration: full browser CORS flow, wildcard policy, preflight caching
|
@menawar Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #1000
This PR implements CORS policy management with dynamic origin whitelisting as described in issue #1000.
Changes
backend/services/shared/index.tsExported all CORS policy management symbols from the shared barrel so any service or consumer can import them cleanly without deep path imports.
backend/server.tsprocessCorsRequestfrom the CORS middlewareOPTIONSpreflight requests with a204 No Content(or403if the origin is blocked)CORS_ALLOWED_ORIGINenvironment variable on server startupGET /cors/analyticsendpoint exposing CORS telemetryGET /cors/violationsendpoint for querying blocked request logsbackend/services/shared/__tests__/corsMiddleware.test.ts(new)Comprehensive test suite with 47 unit and integration tests covering:
upsertPolicy,getPolicy,getAllPolicies,deletePolicy)testOriginprocessCorsRequestfor simple andOPTIONSpreflight requestsclearPreflightCachegetViolationsfiltering by tenant, origin, limit, and since-timestampcreateCorsMiddlewareExpress-style factoryresetAnalyticsTest Results
Acceptance Criteria