IN PROGRESS
Technical summary
Native NEXUS plugin that centralizes Cross-Origin Resource Sharing control for the public api.php (general API) and p.php (OCI proxy) endpoints, replacing the static CORS blocks with panel-managed rules. Each endpoint has independent enabled, allow_all, origins, allow_headers and allow_methods settings, runtime origin resolution (including a same-origin fallback to the panel) and integration with declarative requirements that plugins expose through cors.php — applied automatically with one click.
Executed scope
backend.phpbackend (269 lines):cors_get_config()with defaults inDB::getConfig('plugin.cors')for theapiandproxyendpoints;cors_save_config()with sanitization (trim, empty filtering and methods normalized to uppercase) persisted inadmin_configs— no dedicated tables.- Runtime origin resolution (
cors_get_origin): plugin disabled →*;allow_all→*; no origins configured → same origin (SITE_URL); otherwise it matchesHTTP_ORIGINagainst the allowlist (ignoring trailing slash) with a same-origin fallback. cors_apply_headers($endpoint)emitsAccess-Control-Allow-Origin/Headers/Methods; applied inapi.php:39(api) andp.php:19(proxy), with the previous static blocks kept as fallback while the plugin is inactive.- Declarative requirements: any plugin can expose
cors.php(endpoint,label,origins,methods,headers,reason,help);cors_get_plugin_requirements()scansplugins/*/cors.phpwith a static cache and evaluatesmetper endpoint against the current configuration. - 5 plugins already declare requirements:
aikido,github,nexus-security-scannerandvirustotalon the api endpoint;oci-cloud-storageon the proxy — with origins such asapp.aikido.dev,api.github.comandwww.virustotal.comand headers such asX-Hub-Signature-256andx-apikey. - Automatic application:
cors_apply_requirement($slug)injects the required origins/methods/headers into the matching rule and persists it;cors_requirements_met()andcors_render_warning()let other plugin tabs show a pending-configuration banner with a "Configure" button. - API: 4 actions registered via
PluginManager::registerApiAction—cors_get_config,cors_save_config,cors_get_requirements,cors_apply_requirement(session/Bearer authenticated with CSRF). - Alpine.js UI (
tab.php327 lines +modals.php247 lines): per-endpoint cards (General APIapi.php/ OCI Proxyp.php) with enable toggle, "Allow All" mode with an amber warning, editable origin list, header and method chips, a terminal-style Effective CORS preview, a "Plugin Requirements" section with anx/y OKcounter, Active/Inactive badges and an "Configure Automatically" button, a status indicator (inactive / API / Proxy / API+Proxy, amber on allow-all), a sticky save bar with Reset, and a reusable modal opened via thecors-configure.windowevent. - fastr
/corscommand →cors_get_requirements(no required argument) andcronjob.jsonwith no routines (on-demand plugin).
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (settings in
admin_configs; no dedicated tables) - Alpine.js + Tailwind CSS
- NEXUS plugin system (
PluginManager)
Operational tags
- CORS
- API
- Security
- Proxy
Operational outcome
- Centralized NEXUS CORS control:
api.phpandp.phpnow respond according to panel-managed rules instead of per-file static blocks. - Runtime origin resolution removes the insecure
Access-Control-Allow-Origin: *: with the plugin active, access can be restricted by origin with a safe same-origin fallback. - Declarative requirements: integrations that need CORS (Aikido, GitHub, VirusTotal, Security Scanner, OCI) declare what they require and the panel shows exactly what is missing — applied with one click.
- Protection against accidental permissive configuration: "Allow All" mode shows a warning in the UI and turns the status indicator amber.
- No new tables: configuration persisted in
admin_configsviaDB::getConfig/setConfig.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Native NEXUS plugin (is_core) for Cross-Origin Resource Sharing control of the api.php (API) and p.php (OCI proxy) endpoints, with per-endpoint allowed origins, headers and methods, runtime origin resolution and one-click application of requirements declared by plugins.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.