fix(docker): configure CORS origins for frontend in Docker Compose - #2333
Open
anshul23102 wants to merge 1 commit into
Open
fix(docker): configure CORS origins for frontend in Docker Compose#2333anshul23102 wants to merge 1 commit into
anshul23102 wants to merge 1 commit into
Conversation
Adds SECUSCAN_CORS_ALLOWED_ORIGINS environment variable to the api service in docker-compose.yml, explicitly configuring which browser origins are allowed to make requests to the backend API. Previously, CORS relied on backend defaults. This explicitly sets the allowed origins to localhost and 127.0.0.1 on common dev/test ports (5173, 3000, 8080), ensuring the frontend can communicate with the backend in containerized environments. Excludes Docker service names (e.g. http://frontend:5173) since they are internal to the container network and not accessible from browsers. Adds integration test to validate CORS configuration from environment variables.
Contributor
Author
|
This is a clean, focused version addressing the Docker/CORS configuration feedback. The previous PR #1700 accumulated unrelated changes; this version contains only:
All CI checks passing. Ready for review. |
utksh1
requested changes
Aug 4, 2026
utksh1
left a comment
Owner
There was a problem hiding this comment.
The added tests only instantiate Settings after mutating os.environ; they do not validate the docker-compose configuration that this PR changes, and the process-wide environment mutation can leak into later tests. Please use pytest's monkeypatch fixture and add coverage that verifies the Compose-provided SECUSCAN_CORS_ALLOWED_ORIGINS value (or otherwise test the actual configuration boundary). Keep the test focused on the behavior this PR changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds SECUSCAN_CORS_ALLOWED_ORIGINS environment variable to the api service in docker-compose.yml for explicit CORS configuration.
Previously, CORS relied on backend defaults. This change explicitly sets allowed origins to localhost and 127.0.0.1 on common dev/test ports (5173, 3000, 8080), ensuring the frontend can communicate with the backend in containerized environments.
Excludes Docker service names (e.g. http://frontend:5173) since they are internal to the container network and not accessible from browsers.
Includes integration test to validate CORS configuration from environment variables.
GSSoC 2026