Skip to content

fix!: disable server.cors by default for security reasons#4399

Merged
chenjiahan merged 2 commits intomainfrom
cors_default_0120
Jan 20, 2025
Merged

fix!: disable server.cors by default for security reasons#4399
chenjiahan merged 2 commits intomainfrom
cors_default_0120

Conversation

@chenjiahan
Copy link
Copy Markdown
Member

Summary

This PR follows Vite's security patches to disallow fetching from untrusted origins.

Although this is a breaking change, considering that server.cors was newly added in version v1.1.11, it's unlikely that many users are relying on this behavior.

See:

Checklist

  • Tests updated (or not required).
  • Documentation updated (or not required).

@netlify
Copy link
Copy Markdown

netlify bot commented Jan 20, 2025

Deploy Preview for rsbuild ready!

Name Link
🔨 Latest commit 2ea2390
🔍 Latest deploy log https://app.netlify.com/sites/rsbuild/deploys/678e53a6be43450008250e77
😎 Deploy Preview https://deploy-preview-4399--rsbuild.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 76 (🟢 up 2 from production)
Accessibility: 97 (no change from production)
Best Practices: 100 (no change from production)
SEO: 100 (no change from production)
PWA: 60 (no change from production)
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify site configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant