rubyforgood / rubyforgood/alongwithyou

Wide-open dev CORS with no auth in front

Open Beginner friendly
#85 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

severity:significant
Dominant language
TypeScript
Stars
9
Forks
4
Avg merge
9h 34m
Merged PRs (30d)
16

Description

Verified: a preflight from http://evil.example.com gets 200 and Access-Control-Allow-Origin: *, since Rails.env.local? covers both development and test. Any page a developer visits while bin/rails server is running can read and delete their local data. Narrow dev origins to localhost/LAN patterns.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the CORS configuration used when running bin/rails server and inspect how Rails.env.local? enables the wildcard origin. Reproduce the preflight from the issue, then verify that localhost/LAN origins remain allowed while evil.example.com cannot read or delete local data.

Written by the indexing model from the issue text.

Assessment

Tech stack
rails, ruby
Domain
backend, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.