did-btcr2-js

ADR 031: Permissive CORS by Default

Status: Accepted

Date: 2026-04-22

Branch / PR: aggregation/http-transport Depends on: ADR 028, ADR 029

Context

HttpServerTransport needs to decide a default CORS policy. Two deployment shapes are common:

The standard CORS concern is a site at evil.example.com making authenticated requests against a service the user has session cookies for, using ambient cookie authority. This attack (CSRF) does NOT apply to our transport because:

evil.example.com can at most fetch public endpoints (GET /v1/adverts, GET /v1/.well-known/aggregation), neither of which exposes secrets.

Options considered

  1. Same-origin only. Safest by reflex; blocks the cross-origin wallet use case entirely.
  2. Allowlist by default. Operators configure specific origins. Ecosystem integration requires per-wallet negotiation.
  3. Permissive (Access-Control-Allow-Origin: *). Any webapp from any origin can interact with the transport.

Decision

Option 3. Default CorsPolicy is { mode: 'permissive' }. The server emits Access-Control-Allow-Origin: * on all responses (including OPTIONS preflights). Config can tighten to { mode: 'allowlist', origins: [...] } or { mode: 'same-origin' }.

Consequences

Positive

Negative

Explicitly accepted trade-offs

References