Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !7

Merged
Opened Jul 24, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

security: make trust proxy and CORS origins configurable

Tóm tắt thay đổi (Summary of Changes)

  • Bảo mật IP (Trust Proxy): Chuyển cấu hình trust proxy từ mặc định true sang cấu hình động qua biến môi trường TRUST_PROXY (mặc định là false). Điều này ngăn chặn kẻ tấn công tự giả mạo header X-Forwarded-For để bypass rate limit hoặc làm sai lệch audit log khi ứng dụng không thực sự đứng sau một reverse proxy tin cậy.
  • Giới hạn CORS: Thay thế việc mở CORS hoàn toàn (*) bằng whitelist động qua biến môi trường ALLOWED_ORIGINS. Hỗ trợ cấu hình nhiều tên miền cụ thể của frontend và bật tính năng truyền cookie/credentials an toàn.
  • Cấu hình: Cập nhật file .env.example và .env mẫu để dễ dàng thiết lập ở các môi trường khác nhau.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b security/trust-proxy-cors-hardening origin/security/trust-proxy-cors-hardening

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff security/trust-proxy-cors-hardening

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 3
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!7

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.