en86

en86

My understanding is that http headers can be spoofed but CORS policies are considered a legitimate security measure in term of trusting the origin of a request.

I’m inspecting the conn struct of a request made by my Phoenix application and trying to figure out how to think about a CORS policy.

I see the following:

  • In headers map: “sec-fetch-site” => “same-origin”
  • In req_headers: {“sec-fetch-site”, “same-origin”}
  • In resp_headers: {“x-frame-options”, “SAMEORIGIN”} and {“cross-origin-window-policy”, “deny”}
  • There are several places where a “host” or “referer” are referenced that have the URL of the request

I assume “host” and “referer” headers can’t be trusted?

Is the req_header of {“sec-fetch-site”, “same-origin”} what indicates that it’s a same-origin request (e.g., the browser sends that if it confirms it’s same-origin?). If so, I assume that can be trusted?

Is there anyway to get the URL of a request from a trusted header or is a same-origin marker the best that can be done?

It looks like there are a couple hex packages that deal with CORS but I was hoping to understand exactly how the request process here works with Phoenix (and better understand how CORS works).

Thanks in advance for any help on this!

Showing Posts 1 to 1

derek-zhou

derek-zhou

I think no headers, including origin, can be trusted; you can trust your own credentials (like cookies). I just return whatever origin presented in the incoming requests (to make browser happy) and check cookies using normal authentication practices.

If the cookie was stolen then is is not the server side’s fault anyway.

— All posts loaded —

Where Next? Top

Trending in Discussions Top

AstonJ
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
2977 94592 917
New
cblavier
Hey there, It’s been more than a year since we started using LiveView as our main UI library and building a whole library of UI componen...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
heathen
Quite interesting article Google brought me. Didn’t find any mentions about it here. What do you think in general? Would you use togethe...
New
maennchen
:warning: Security advisory: Decimal DoS vulnerability A vulnerability has been published for decimal where very large exponents can cau...
New
marciol
It would be helpful to have a list of companies worldwide that hire engineers without prior experience in Elixir. Often, it can be quite ...
New
durvia
Anyone running long-lived stateful processes on BEAM? We’re building an AI agent runtime and would love to compare notes. We’re a small ...
New

Other Trending Topics Top

marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
webofbits
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself. My main conc...
#ai
New
webofbits
Aludel - LLM Evaluation Workbench Aludel is an embeddable Phoenix LiveView dashboard for evaluating and comparing LLM prompts across mult...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews