All fixes

Stop reflecting origins on private APIs

cors-auth-reflect

Your authenticated endpoints echo the calling origin back and send session cookies with the reply, so any page a user visits can read their data.

Why this matters

Your logged-in API endpoints echo back whatever website asks to read them, and include your users' session cookies. It's like a bank teller who hands account details to anyone who asks, as long as the customer is standing nearby. Any malicious page can silently steal your users' private data.

Express

  1. 1 Your authenticated API endpoints reflect the Origin header
  2. 2 Apply the same CORS fix as cors-origin-reflect to your API routes
javascript
// Ensure API routes use explicit origin lists
app.use("/api", cors({
  origin: ["https://app.example.com"],
  credentials: true,
}));

Does your app still have this?

Scan your domain