All fixes

Fix a wildcard CORS origin with cookies

cors-wildcard-creds

A wildcard allow-origin combined with credentials is rejected by browsers, so the cross-origin calls you meant to allow just fail. Name the origin.

Why this matters

Your server sends Access-Control-Allow-Origin: * with credentials, but browsers block this combination per the CORS spec. The attack cannot succeed. Still a misconfiguration worth fixing.

Nginx

  1. 1 Never combine Access-Control-Allow-Origin: * with Allow-Credentials: true
  2. 2 Use a map to allowlist specific origins
nginx
# Remove:
#   add_header Access-Control-Allow-Origin * always;
#   add_header Access-Control-Allow-Credentials true always;
# Replace with origin allowlist (see cors-origin-reflect fix)

Does your app still have this?

Scan your domain