Fix cross-origin policy accepts any origin in Astro
The CORS configuration accepts requests from any origin. Combined with credentials this lets any site a logged-in user visits make authenticated calls to the API and read the responses. Without credentials it may be intentional for a public API - the finding says which case it found.
medium likely Astro CWE-942 / OWASP A05:2021
The vulnerable pattern in Astro
This finding comes from the Astro fixture in the owlwarden test
suite, in /api/users.
Any origin may call this API and read the response. That is a deliberate choice for a public endpoint and a mistake for anything behind a session - nothing in the source says which this is, so it is reported for you to decide.
The corrected handler
Set the header explicitly in the endpoint rather than reflecting the caller's origin.
// src/pages/api/data.ts
const ALLOWED_ORIGIN = 'https://app.example.com'
export async function GET({ request }: APIContext) {
const origin = request.headers.get('origin')
const headers = new Headers()
if (origin === ALLOWED_ORIGIN) {
headers.set('Access-Control-Allow-Origin', ALLOWED_ORIGIN)
headers.set('Vary', 'Origin')
}
return new Response(JSON.stringify({ ok: true }), { headers })
}
If you are not using Astro
Replace the wildcard with the origins that actually need access, and only send credentials to those.
Check your own repository
npx owlwarden scan
npx owlwarden explain cors-permissive
Runs on your machine. No account, no telemetry, no network unless you ask. In CI, SARIF uploads to code scanning and the exit code is the gate.
Other Astro checks
Rules with a tested Astro example.
- hardcoded-secret high Credential hardcoded in source
- insecure-cookie medium Cookie set without its protective attributes
- install-lifecycle-script medium Package declares an install-time script
- open-redirect medium Redirect target comes from the caller
- security-headers-missing medium Security headers are not configured
- sensitive-data-logged medium Sensitive data written to a log
- sql-injection high SQL query built by string interpolation
- ssrf high Server fetches a URL the caller controls
- stack-trace-leak high Stack trace leaked in error response
- weak-crypto high Broken cryptographic primitive protecting a secret