Files
probo/pkg
Bryan Frimin ea21f85887 Add http.CrossOriginProtection for CSRF defense using Sec-Fetch-Site headers
Implements native Go 1.26 cross-origin protection to block state-changing cross-origin browser requests. Registers configured AllowedOrigins as trusted origins and wraps the API router to check all incoming requests. Non-browser clients (MCP, Slack webhooks) are unaffected as they lack the browser-only Sec-Fetch-Site header.

Signed-off-by: gearnode <gearnode@probo.inc>
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-19 09:31:52 +01:00
..
2026-03-16 00:28:47 +01:00
2026-03-06 15:00:42 +01:00
2026-03-16 00:28:47 +01:00
2026-02-02 18:42:50 +01:00
2026-03-13 17:18:02 +01:00
2026-03-06 15:00:42 +01:00
2026-03-13 17:18:02 +01:00
2026-03-13 14:48:13 +01:00
2026-01-17 12:34:23 -08:00
2025-11-20 19:25:29 +01:00
2026-03-16 00:28:47 +01:00
2026-03-13 17:18:02 +01:00
2025-07-14 12:38:07 +02:00
2026-03-16 00:28:47 +01:00
2026-03-16 00:28:47 +01:00
2025-12-15 18:24:00 +01:00
2026-03-13 14:48:13 +01:00