- Removed manual 'Access-Control-Allow-Origin: *' setHeader calls - Now using cors middleware with ALLOWED_ORIGINS env variable - CORS can be restricted via environment configuration Security improvement from Wave 2 pentest. Date: 2026-01-26 |
||
|---|---|---|
| .. | ||
| services | ||
| cli.js | ||
| server.js | ||