SCRUM-201 — gateway_dev: remove unused CORS config¶
Plan ref: GWD-4 (docs/11-admin-plane-plan.md). Stacked on SCRUM-200.
What changed¶
GATEWAY_DEV_CORS_ALLOWED_ORIGINS was parsed into Config.CORSAllowedOrigins and
never read. The admin UI is served at /admin/ by gateway_dev itself, so every
browser call is same-origin and CORS is never needed. Removed:
| Removed | Where |
|---|---|
CORSAllowedOrigins field and the env read |
services/gateway_dev/internal/config/config.go |
CORS origins subtest |
services/gateway_dev/internal/config/config_test.go |
| the variable and its comment | services/gateway_dev/.env.example |
| env table row; "gap" bullet; reworded the "what exists" line to say CORS is absent on purpose | services/gateway_dev/README.md |
| env table row and two CORS mentions | docs/05-gateway-techspec.md |
Behaviour is unchanged: nothing read the value, and an old deployment that still sets the variable just has it ignored (the loader does not reject unknown vars).
How to verify¶
cd services/gateway_dev
grep -rn -i cors . # only README.md:17 ("no CORS middleware because the admin UI is same-origin")
go vet ./... && go test -race -count=1 ./...
bash testdata/smoke/smoke.sh | grep -c FINDING # 0
grep -rn -i cors ../../deploy # nothing
Results at time of writing¶
go vet,go test -race: pass (3 packages).smoke.sh: 0 findings.deploy/: no CORS reference to clean up.
How it was built¶
Implemented by a DeepSeek run scoped (Landlock) to services/gateway_dev; reviewed
and finished by Claude (README line reflow, docs/05 edits outside that scope).
Run log: 35 s, ~2.7k output tokens.