Stop reflecting origins on private APIs
cors-auth-reflect
Your authenticated endpoints echo the calling origin back and send session cookies with the reply, so any page a user visits can read their data.
Why this matters
Your logged-in API endpoints echo back whatever website asks to read them, and include your users' session cookies. It's like a bank teller who hands account details to anyone who asks, as long as the customer is standing nearby. Any malicious page can silently steal your users' private data.
Frameworks
Express
- 1 Your authenticated API endpoints reflect the Origin header
- 2 Apply the same CORS fix as cors-origin-reflect to your API routes
javascript
// Ensure API routes use explicit origin lists
app.use("/api", cors({
origin: ["https://app.example.com"],
credentials: true,
}));Does your app still have this?
Scan your domain