All fixes

Stop reflecting the CORS request origin

cors-origin-reflect

Your server echoes back whatever Origin asks, which turns the CORS allowlist into a rubber stamp. Compare the origin against a fixed list.

Cloudflare

  1. 1 Use Transform Rules to set a static Access-Control-Allow-Origin
  2. 2 Or handle CORS logic in a Cloudflare Worker
javascript
// Cloudflare Worker example
const ALLOWED = new Set(["https://app.example.com"]);
addEventListener("fetch", event => {
  const origin = event.request.headers.get("Origin");
  if (ALLOWED.has(origin)) {
    response.headers.set("Access-Control-Allow-Origin", origin);
  }
});

Does your app still have this?

Scan your domain