memos/server
boojack 385fa22056 fix(cors): open API to any origin for token auth, keep cookies same-origin
Reflect any Origin so token-authenticated clients (Access Token V2 / PAT)
can call the API cross-origin, but emit Access-Control-Allow-Credentials
only for trusted origins (same host / configured InstanceURL). This keeps
the SameSite=Lax refresh cookie unreadable by untrusted (incl. same-site
subdomain) origins. Origin: null is not reflected.

Note for operators: cross-origin token access is now open by default; if
you front memos with a caching proxy, ensure it honors `Vary: Origin`.
2026-06-14 23:20:34 +08:00
..
auth fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
notification feat(notification): add smtp email settings 2026-05-01 18:48:21 +08:00
router docs: add README for mcp 2026-06-09 23:54:58 +08:00
runner fix(s3presign): preserve motion media payload 2026-05-09 22:51:56 +08:00
cors.go fix(cors): open API to any origin for token auth, keep cookies same-origin 2026-06-14 23:20:34 +08:00
cors_test.go fix(cors): open API to any origin for token auth, keep cookies same-origin 2026-06-14 23:20:34 +08:00
server.go feat: add OpenAPI-driven MCP support (#6026) 2026-06-09 09:16:50 +08:00