From fa73d45b41e0c101de1b4ecb5aa644b24920f6c3 Mon Sep 17 00:00:00 2001 From: ShadowArcanist <162910371+ShadowArcanist@users.noreply.github.com> Date: Fri, 3 Apr 2026 19:26:06 +0530 Subject: [PATCH] fix dangerous cors config for directus service --- templates/compose/directus.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/templates/compose/directus.yaml b/templates/compose/directus.yaml index 5c02ab1a3..1648f7e3d 100644 --- a/templates/compose/directus.yaml +++ b/templates/compose/directus.yaml @@ -23,7 +23,7 @@ services: - DB_FILENAME=/directus/database/data.db - WEBSOCKETS_ENABLED=true - CORS_ENABLED=${CORS_ENABLED:-true} - - CORS_ORIGIN=${CORS_ORIGIN:-true} + - CORS_ORIGIN=${CORS_ORIGIN} - CORS_METHODS=${CORS_METHODS:-GET,POST,PATCH,DELETE,OPTIONS} - CORS_ALLOWED_HEADERS=${CORS_ALLOWED_HEADERS:-Content-Type,Authorization} - CORS_CREDENTIALS=${CORS_CREDENTIALS:-true}