Reflect any Origin so token-authenticated clients (Access Token V2 / PAT) can call the API cross-origin, but emit Access-Control-Allow-Credentials only for trusted origins (same host / configured InstanceURL). This keeps the SameSite=Lax refresh cookie unreadable by untrusted (incl. same-site subdomain) origins. Origin: null is not reflected. Note for operators: cross-origin token access is now open by default; if you front memos with a caching proxy, ensure it honors `Vary: Origin`. |
||
|---|---|---|
| .. | ||
| auth | ||
| notification | ||
| router | ||
| runner | ||
| cors.go | ||
| cors_test.go | ||
| server.go | ||