Commit e8e6c1e
committed
fix: CORS startup crash + path traversal security
- CORS: change allow_credentials=True to False (wildcard origins + credentials is forbidden by Starlette, causes AssertionError on boot)
- Path traversal: already fixed with is_relative_to (was in diff from prior session)1 parent 9d41ac5 commit e8e6c1e
2 files changed
+2
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
76 | | - | |
| 76 | + | |
77 | 77 | | |
78 | 78 | | |
79 | 79 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
130 | | - | |
| 130 | + | |
131 | 131 | | |
132 | 132 | | |
133 | 133 | | |
| |||
0 commit comments