curl -sI -H 'Origin: https://ethicsengine.org' https://api.ethicsengine.org/api/v1/scores returns:
access-control-allow-origin: *
access-control-allow-credentials: true
access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS
vary: Origin
Per the Fetch spec, a wildcard origin with credentials: true is invalid; browsers block any request made with credentials: 'include' (cookies, or Authorization on some paths). Public anonymous GETs work today, which is why the scores page renders — but any authenticated browser call from ethicsengine.org or the admin UI to this API cross-origin will fail with a CORS error rather than a 401.
Fix: enumerate the allowed origins (https://ethicsengine.org, https://admin.ethicsengine.org, https://node.ciris.ai, https://portal.ethicsengine.org, localhost dev ports) and echo the matching one, or drop allow_credentials if the API is bearer-token only and never uses cookies. Check CORSMiddleware(allow_origins=["*"], allow_credentials=True, …) in cirisnode/main.py.
Found during the 2026-09-24 site audit.
curl -sI -H 'Origin: https://ethicsengine.org' https://api.ethicsengine.org/api/v1/scoresreturns:Per the Fetch spec, a wildcard origin with
credentials: trueis invalid; browsers block any request made withcredentials: 'include'(cookies, orAuthorizationon some paths). Public anonymous GETs work today, which is why the scores page renders — but any authenticated browser call fromethicsengine.orgor the admin UI to this API cross-origin will fail with a CORS error rather than a 401.Fix: enumerate the allowed origins (
https://ethicsengine.org,https://admin.ethicsengine.org,https://node.ciris.ai,https://portal.ethicsengine.org, localhost dev ports) and echo the matching one, or dropallow_credentialsif the API is bearer-token only and never uses cookies. CheckCORSMiddleware(allow_origins=["*"], allow_credentials=True, …)incirisnode/main.py.Found during the 2026-09-24 site audit.