Skip to content

fix: allow csrf token in cors headers - #345

Merged
kunalverma2512 merged 1 commit into
mainfrom
fix_cors
Sep 14, 2026
Merged

kunalverma2512 merged 1 commit into
mainfrom
fix_cors

Conversation

@kunalverma2512

Copy link
Copy Markdown
Owner

Description

This pull request fixes a critical connection issue occurring in the production environment. When a user tried to connect their Codeforces account, the browser blocked the request because the CSRF token header was missing from the allowed headers list.

Root Cause

The backend security configuration was extremely strict and only allowed the Content Type and Authorization headers to pass through during preflight checks.

Changes Made

  • Updated the allowed headers array inside the main server file.
  • Explicitly included the CSRF token header in the allowed list.
  • The frontend can now securely send the token, and the Codeforces connection will work perfectly in production without being blocked.

@vercel

vercel Bot commented Sep 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
codelensx Ready Ready Preview Sep 14, 2026 9:45am UTC

@github-actions

Copy link
Copy Markdown

🎉 Welcome to CodeLens — Thank You for Your Contribution!

Hey @kunalverma2512! 👋

We are genuinely excited to have you here. Every single PR — big or small — makes CodeLens better, and yours is no exception. Take a moment to review the checklist below to help us merge your work quickly and smoothly.

✅ Before Requesting a Review

  • Keep code clean, readable, and consistent with the existing codebase
  • Avoid unrelated or unnecessary file changes
  • Make sure the UI is fully responsive across all device sizes
  • Attach screenshots or a short screen recording for any UI changes
  • Resolve all merge conflicts before marking the PR as ready
  • Do not submit AI-generated, copy-pasted, or low-effort implementations

💬 Join Our Community Channel — This is Mandatory

Being part of our communication channel is compulsory for all contributors, not optional.

📡 Join the CodeLens Matrix Channel

Why join? This is where all important announcements, PR review updates, contribution discussions, and maintainer decisions happen in real time. Contributors who are not in the channel regularly miss critical context and updates, which often leads to duplicated or misaligned work. Staying connected here is what keeps the community strong and your contributions impactful.


We are rooting for you! If you have any questions, drop them in the channel or comment right here on this PR. Let's build something great together. 🚀✨

@codecov

codecov Bot commented Sep 14, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kunalverma2512
kunalverma2512 merged commit 620d229 into main Sep 14, 2026
10 checks passed

This branch was successfully deployed

1 active deployment
Preview — 1f64bc59 Deployed Sep 14, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant