Skip to content

Reject null origins on SSE events endpoint#7

Closed
0x4D31 wants to merge 1 commit intomainfrom
review-and-fix-sse-server-security-issue
Closed

Reject null origins on SSE events endpoint#7
0x4D31 wants to merge 1 commit intomainfrom
review-and-fix-sse-server-security-issue

Conversation

@0x4D31
Copy link
Owner

@0x4D31 0x4D31 commented Nov 4, 2025

Summary

  • stop accepting Origin: null on the SSE events handler so only same-host origins are permitted
  • keep the focused CORS tests that cover matching and disallowed origins without null-specific cases

Testing

  • go test ./internal/sse -count=1

https://chatgpt.com/codex/tasks/task_e_690a210f9db4833180f282f400d90b67

@0x4D31 0x4D31 closed this Nov 4, 2025
@0x4D31 0x4D31 deleted the review-and-fix-sse-server-security-issue branch November 4, 2025 16:41
@0x4D31 0x4D31 restored the review-and-fix-sse-server-security-issue branch November 4, 2025 16:48
@0x4D31 0x4D31 reopened this Nov 4, 2025
@0x4D31 0x4D31 closed this Nov 4, 2025
@0x4D31 0x4D31 deleted the review-and-fix-sse-server-security-issue branch November 4, 2025 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant