feat(api): configure CORS middleware for API endpoints
- Add CORSMiddleware (disabled by default, enabled via CORS_ENABLED=true) - Add cors_enabled, cors_allowed_origins, cors_allow_credentials, cors_allowed_methods, cors_allowed_headers settings to config.py - Add parse_comma_separated_list validator for CORS list env vars - Insert CORS middleware between SessionMiddleware and ProxyHeaders so preflight runs before CSRF/auth but after proxy-header processing - Document CORS env vars in .env.demo with rationale for proxy-first approach - Mark CORS TODO as completed in SECURITY_AUDIT.md - Add tests/test_cors.py with 12 unit and integration tests Closes #175 Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
@@ -53,6 +53,32 @@ MAX_UPLOAD_SIZE=1073741824
|
||||
# Always set to 'nosniff' when enabled
|
||||
# SECURITY_HEADER_X_CONTENT_TYPE_OPTIONS_ENABLED=true
|
||||
|
||||
# **CORS (Cross-Origin Resource Sharing)** (see SECURITY_AUDIT.md – Infrastructure Security)
|
||||
# Disabled by default: most deployments rely on a reverse proxy (Traefik, Nginx, etc.) to inject
|
||||
# CORS headers. Set CORS_ENABLED=true only if DocuElevate is exposed directly without a proxy,
|
||||
# or if your proxy does not handle CORS. When enabled, only list the exact origins that need access.
|
||||
#
|
||||
# Rationale for reverse-proxy-first approach:
|
||||
# Traefik/Nginx already set Access-Control-Allow-Origin (and related headers) for every response,
|
||||
# so adding the middleware here would duplicate headers. When this flag is False the application
|
||||
# trusts the proxy layer to enforce CORS policy; set it to True for standalone / direct-access
|
||||
# deployments only.
|
||||
#
|
||||
# CORS_ENABLED=false
|
||||
#
|
||||
# Comma-separated list of allowed origins (use * to allow all - not recommended with credentials)
|
||||
# CORS_ALLOWED_ORIGINS=https://app.example.com,https://admin.example.com
|
||||
#
|
||||
# Allow cookies / Authorization headers in cross-origin requests
|
||||
# Must be False when CORS_ALLOWED_ORIGINS=* (browser security requirement)
|
||||
# CORS_ALLOW_CREDENTIALS=false
|
||||
#
|
||||
# Allowed HTTP methods (comma-separated)
|
||||
# CORS_ALLOWED_METHODS=GET,POST,PUT,DELETE,OPTIONS,PATCH
|
||||
#
|
||||
# Allowed request headers (use * to allow all)
|
||||
# CORS_ALLOWED_HEADERS=*
|
||||
|
||||
# **Rate Limiting** (see SECURITY_AUDIT.md and docs/API.md)
|
||||
# Protects against DoS attacks and API abuse by limiting request rates per IP/user
|
||||
# Enabled by default - highly recommended for production
|
||||
|
||||
Reference in New Issue
Block a user