Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix!: disable server.cors by default for security reasons #4399

Merged
merged 2 commits into from
Jan 20, 2025

Conversation

chenjiahan
Copy link
Member

Summary

This PR follows Vite's security patches to disallow fetching from untrusted origins.

Although this is a breaking change, considering that server.cors was newly added in version v1.1.11, it's unlikely that many users are relying on this behavior.

See:

Checklist

  • Tests updated (or not required).
  • Documentation updated (or not required).

Copy link

netlify bot commented Jan 20, 2025

Deploy Preview for rsbuild ready!

Name Link
🔨 Latest commit 2ea2390
🔍 Latest deploy log https://app.netlify.com/sites/rsbuild/deploys/678e53a6be43450008250e77
😎 Deploy Preview https://deploy-preview-4399--rsbuild.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 76 (🟢 up 2 from production)
Accessibility: 97 (no change from production)
Best Practices: 100 (no change from production)
SEO: 100 (no change from production)
PWA: 60 (no change from production)
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify site configuration.

@chenjiahan chenjiahan merged commit 306528d into main Jan 20, 2025
9 checks passed
@chenjiahan chenjiahan deleted the cors_default_0120 branch January 20, 2025 13:58
@chenjiahan chenjiahan mentioned this pull request Jan 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant