ionic-team / ionic-team/ionic-docs

CORS headers security implications should be more specific

オープン
#2,255 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
triage
主要言語
MDX
スター
621
フォーク
3.2k
平均マージ
1日 2時間
マージ済み PR(30日)
86

説明

**URL**
https://ionicframework.com/docs/troubleshooting/cors#a-enabling-cors-in-a-server-you-control

**What is missing or inaccurate about the content on this page?**
The docs state, "_Allowing any origin with Access-Control-Allow-Origin: * is guaranteed to work in all scenarios but may have security implications — like some CSRF attacks — depending on how the server controls access to resources and use sessions and cookies._".

And that is the only word on the security implications of setting CORS headers. I think the docs need to be more specific and take a stance on whether adding the Access-Control-Allow-Origin header set to http://localhost (or whatever the protocol and hostname is), is safe/unsafe.

This is my interpretation.... If the content the server is serving is not sensitive then it is safe to add the headers. Otherwise, I would not want to add the headers and the native http plugin should be used. This is because a malicious site could be running at localhost in the browser, opening up CSRF attacks.

I think being more specific and transparent here is the best approach and will improve security.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with the linked CORS troubleshooting page, especially the section on enabling CORS in a server you control. Review the explanation of Access-Control-Allow-Origin for localhost, sensitive content, sessions, cookies, and CSRF. Done means the page gives specific, transparent guidance about the security implications and when to use the native HTTP plugin.

索引モデルが issue の本文から書いたものです。

評価

領域
documentation, security
issue の種類
ドキュメント
難易度
2/5
見積もり時間
1〜3時間
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
42/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。