Closed lmanul closed 4 years ago
@DavidMStraub @FiloSottile
Great idea. This should solve the problem discussed in #5 without compromising security in production.
Surely there's no reason to open it up so much. You can limit the origins by host and port.
Good point @ryneeverett, maybe I was a bit too quick merging it, but at least the development setup works again now...
Thank you for merging! I can definitely work on restricting this a little more, but I think as long as anyone running this in debug mode is aware of the risk, I think we're clear of the main concern here.
...and print an explicit warning.