Cover image for project: Nexus CORS IN PROGRESS

Technical summary

Native NEXUS plugin that centralizes Cross-Origin Resource Sharing control for the public api.php (general API) and p.php (OCI proxy) endpoints, replacing the static CORS blocks with panel-managed rules. Each endpoint has independent enabled, allow_all, origins, allow_headers and allow_methods settings, runtime origin resolution (including a same-origin fallback to the panel) and integration with declarative requirements that plugins expose through cors.php — applied automatically with one click.

Executed scope

  • backend.php backend (269 lines): cors_get_config() with defaults in DB::getConfig('plugin.cors') for the api and proxy endpoints; cors_save_config() with sanitization (trim, empty filtering and methods normalized to uppercase) persisted in admin_configs — no dedicated tables.
  • Runtime origin resolution (cors_get_origin): plugin disabled → *; allow_all → *; no origins configured → same origin (SITE_URL); otherwise it matches HTTP_ORIGIN against the allowlist (ignoring trailing slash) with a same-origin fallback.
  • cors_apply_headers($endpoint) emits Access-Control-Allow-Origin/Headers/Methods; applied in api.php:39 (api) and p.php:19 (proxy), with the previous static blocks kept as fallback while the plugin is inactive.
  • Declarative requirements: any plugin can expose cors.php (endpoint, label, origins, methods, headers, reason, help); cors_get_plugin_requirements() scans plugins/*/cors.php with a static cache and evaluates met per endpoint against the current configuration.
  • 5 plugins already declare requirements: aikido, github, nexus-security-scanner and virustotal on the api endpoint; oci-cloud-storage on the proxy — with origins such as app.aikido.dev, api.github.com and www.virustotal.com and headers such as X-Hub-Signature-256 and x-apikey.
  • Automatic application: cors_apply_requirement($slug) injects the required origins/methods/headers into the matching rule and persists it; cors_requirements_met() and cors_render_warning() let other plugin tabs show a pending-configuration banner with a "Configure" button.
  • API: 4 actions registered via PluginManager::registerApiAction — cors_get_config, cors_save_config, cors_get_requirements, cors_apply_requirement (session/Bearer authenticated with CSRF).
  • Alpine.js UI (tab.php 327 lines + modals.php 247 lines): per-endpoint cards (General API api.php / OCI Proxy p.php) with enable toggle, "Allow All" mode with an amber warning, editable origin list, header and method chips, a terminal-style Effective CORS preview, a "Plugin Requirements" section with an x/y OK counter, Active/Inactive badges and an "Configure Automatically" button, a status indicator (inactive / API / Proxy / API+Proxy, amber on allow-all), a sticky save bar with Reset, and a reusable modal opened via the cors-configure.window event.
  • fastr /cors command → cors_get_requirements (no required argument) and cronjob.json with no routines (on-demand plugin).

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (settings in admin_configs; no dedicated tables)
  • Alpine.js + Tailwind CSS
  • NEXUS plugin system (PluginManager)

Operational tags

  • CORS
  • API
  • Security
  • Proxy

Operational outcome

  • Centralized NEXUS CORS control: api.php and p.php now respond according to panel-managed rules instead of per-file static blocks.
  • Runtime origin resolution removes the insecure Access-Control-Allow-Origin: *: with the plugin active, access can be restricted by origin with a safe same-origin fallback.
  • Declarative requirements: integrations that need CORS (Aikido, GitHub, VirusTotal, Security Scanner, OCI) declare what they require and the panel shows exactly what is missing — applied with one click.
  • Protection against accidental permissive configuration: "Allow All" mode shows a warning in the UI and turns the status indicator amber.
  • No new tables: configuration persisted in admin_configs via DB::getConfig/setConfig.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Native NEXUS plugin (is_core) for Cross-Origin Resource Sharing control of the api.php (API) and p.php (OCI proxy) endpoints, with per-endpoint allowed origins, headers and methods, runtime origin resolution and one-click application of requirements declared by plugins.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.