Repository navigation
fix: allow csrf token in cors headers - #345
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
🎉 Welcome to CodeLens — Thank You for Your Contribution!Hey @kunalverma2512! 👋 We are genuinely excited to have you here. Every single PR — big or small — makes CodeLens better, and yours is no exception. Take a moment to review the checklist below to help us merge your work quickly and smoothly. ✅ Before Requesting a Review
💬 Join Our Community Channel — This is MandatoryBeing part of our communication channel is compulsory for all contributors, not optional. Why join? This is where all important announcements, PR review updates, contribution discussions, and maintainer decisions happen in real time. Contributors who are not in the channel regularly miss critical context and updates, which often leads to duplicated or misaligned work. Staying connected here is what keeps the community strong and your contributions impactful. We are rooting for you! If you have any questions, drop them in the channel or comment right here on this PR. Let's build something great together. 🚀✨ |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Description
This pull request fixes a critical connection issue occurring in the production environment. When a user tried to connect their Codeforces account, the browser blocked the request because the CSRF token header was missing from the allowed headers list.
Root Cause
The backend security configuration was extremely strict and only allowed the Content Type and Authorization headers to pass through during preflight checks.
Changes Made