DegrangeM 9472ac4401
Fix vulnerability (#252)
* Improve and simplify code handling CORS

* Don't execute request when origin not allowed

Fix vulnerability

* Remove webCorsOrigin legacy option

It's confusing (and potentially insecure as removing webCorsOrigin in configuration would still set it to localhost)

* Allow 127.0.0.1 and browser extension if localhost allowed
2021-05-05 22:31:11 -07:00
..
2021-05-05 22:31:11 -07:00
2020-01-05 16:24:20 -08:00
2021-05-05 22:31:11 -07:00
2021-05-05 22:31:11 -07:00