INNER CODE UNIT · Python
ALL_ALLOWED_ORIGINS
SHAdd0WTAka/Zen-Ai-Pentest · api/main.py:533
ALL_ALLOWED_ORIGINS = list(set(DEV_ORIGINS + ALLOWED_ORIGINS + CLOUDFLARE_ORIGINS + CLOUDFLARE_TUNNEL_ORIGINS))
def is_origin_allowed(origin: str) -> bool:
"""Prüft ob eine Origin erlaubt ist (inkl. Pattern-Matching)"""
if not origin:
return False
if origin in ALL_ALLOWED_ORIGINS:
return True
if re.match(r"https://[a-z0-9-]+\.zen-alpha-pentest\.pages\.dev", origin):
return True
if re.match(r"https://[a-z-]+\.trycloudflare\.com", origin):
return True
return False
class DynamicCORSProcessor:
"""Middleware um CORS für dynamische Origins zu ermöglichen"""