feat(security): isolate multi-tenant agent audit metrics, restrict CORS origins, exclude sqlite databases from git tracking, and add TDD test suite

This commit is contained in:
vanne committed 2026-07-01 23:26:48 +07:00
1 parent b816c1e570
commit e9f35c5a6b
20 files changed
+1819 -871

No files matched your search

+15 -1
View File
@@ -10,7 +10,21 @@ const app = express();
const PORT = process.env.BACKEND_PORT || 3001;
// ── Middleware ────────────────────────────────────────────────────────────────
app.use(cors({ origin: true, credentials: true }));
const ALLOWED_ORIGINS = process.env.ALLOWED_ORIGINS
? process.env.ALLOWED_ORIGINS.split(',')
: ['http://localhost:3000', 'http://127.0.0.1:3000'];
app.use(cors({
origin: (origin, callback) => {
if (!origin) return callback(null, true);
if (ALLOWED_ORIGINS.includes(origin)) {
callback(null, true);
} else {
callback(new Error('Blocked by CORS policy (Unauthorized Origin)'));
}
},
credentials: true
}));
app.use(express.json());
app.use(cookieParser());