Skip to content

Commit 2eca9e5

Browse files
committed
webpack: Disable cross-origin-header-check middleware.
This middleware in webpack-dev-server 5.2.1 appears to be intended to plug some undisclosed browser-specific vulnerability that allows stealing code from closed-source projects. webpack/webpack-dev-server#5446 (comment) webpack/webpack-dev-server#5446 (comment) Signed-off-by: Anders Kaseorg <[email protected]>
1 parent 8e1e314 commit 2eca9e5

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

web/webpack.config.ts

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -255,6 +255,8 @@ const config = (
255255
"Access-Control-Allow-Origin": "*",
256256
"Timing-Allow-Origin": "*",
257257
},
258+
setupMiddlewares: (middlewares) =>
259+
middlewares.filter((middleware) => middleware.name !== "cross-origin-header-check"),
258260
},
259261
infrastructureLogging: {
260262
level: "warn",

0 commit comments

Comments
 (0)