Description
The image proxy returns Access-Control-Allow-Origin: *, allowing any website to use it.
Affected File
app/api/image-proxy/route.ts
Current Behavior
'Access-Control-Allow-Origin': '*',
Suggested Fix
Restrict to known origins or remove if not needed for cross-origin access:
'Access-Control-Allow-Origin': process.env.ALLOWED_ORIGIN || 'http://localhost:3000',
Description
The image proxy returns
Access-Control-Allow-Origin: *, allowing any website to use it.Affected File
app/api/image-proxy/route.tsCurrent Behavior
Suggested Fix
Restrict to known origins or remove if not needed for cross-origin access: