Skip to content

Restrict SSE events endpoint to trusted origins#8

Merged
0x4D31 merged 1 commit intomainfrom
review-and-fix-sse-server-security-issue
Nov 4, 2025
Merged

Restrict SSE events endpoint to trusted origins#8
0x4D31 merged 1 commit intomainfrom
review-and-fix-sse-server-security-issue

Conversation

@0x4D31
Copy link
Owner

@0x4D31 0x4D31 commented Nov 4, 2025

Summary

  • restrict the SSE events handler to only allow requests from matching or null origins
  • return 403 for disallowed origins to avoid leaking events to arbitrary websites
  • add unit tests covering the new CORS logic

Testing

  • go test ./internal/sse -count=1

https://chatgpt.com/codex/tasks/task_e_690a210f9db4833180f282f400d90b67

@0x4D31 0x4D31 merged commit db48717 into main Nov 4, 2025
1 check passed
@0x4D31 0x4D31 deleted the review-and-fix-sse-server-security-issue branch December 6, 2025 23:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant