Skip to content

Honor disabled CORS in Rails configuration - #218

Merged
dalehamel merged 3 commits into
mainfrom
dale/fix-server-cors
Sep 14, 2026
Merged

dalehamel merged 3 commits into
mainfrom
dale/fix-server-cors

Conversation

@dalehamel

@dalehamel dalehamel commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Summary

The Rails initializer currently applies server_cors || true, which discards an explicitly configured false. Preserve false while keeping CORS enabled when the option is unset or nil.

  • Add isolated regression tests that run the actual app_profiler.configs initializer and check successful /profile response headers for unset, nil, true, false, and custom-origin configurations.
  • Document the Rails CORS opt-out and origin restriction, and clarify that localhost binding and CORS are not authentication.
  • Refresh the repository ownership metadata.

Validation

  • Both explicit-disable regression cases fail against the previous initializer and pass with this fix.
  • bundle exec rake: 255 tests, 851 assertions, no failures or errors (Ruby 3.3.1); also passed with five fixed random seeds.
  • bundle exec rubocop: 71 files inspected, no offenses.

Assisted-By: devx/1cab3837-2abe-4c14-beca-dc50436a5e4e
Assisted-By: devx/1cab3837-2abe-4c14-beca-dc50436a5e4e
Assisted-By: devx/1cab3837-2abe-4c14-beca-dc50436a5e4e
@dalehamel
dalehamel marked this pull request as ready for review September 14, 2026 19:24

@manuelfelipe manuelfelipe left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks. fine for now to address the linked issue.

in any case, as discussed, i think we should just look into fully deprecating and removing the server support as we no longer make use of it

@dalehamel
dalehamel merged commit 108e510 into main Sep 14, 2026
5 checks passed
@dalehamel
dalehamel deleted the dale/fix-server-cors branch September 14, 2026 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants