Skip to content

SCRUM-201 — gateway_dev: remove unused CORS config

Plan ref: GWD-4 (docs/11-admin-plane-plan.md). Stacked on SCRUM-200.

What changed

GATEWAY_DEV_CORS_ALLOWED_ORIGINS was parsed into Config.CORSAllowedOrigins and never read. The admin UI is served at /admin/ by gateway_dev itself, so every browser call is same-origin and CORS is never needed. Removed:

Removed Where
CORSAllowedOrigins field and the env read services/gateway_dev/internal/config/config.go
CORS origins subtest services/gateway_dev/internal/config/config_test.go
the variable and its comment services/gateway_dev/.env.example
env table row; "gap" bullet; reworded the "what exists" line to say CORS is absent on purpose services/gateway_dev/README.md
env table row and two CORS mentions docs/05-gateway-techspec.md

Behaviour is unchanged: nothing read the value, and an old deployment that still sets the variable just has it ignored (the loader does not reject unknown vars).

How to verify

cd services/gateway_dev
grep -rn -i cors .                 # only README.md:17 ("no CORS middleware because the admin UI is same-origin")
go vet ./... && go test -race -count=1 ./...
bash testdata/smoke/smoke.sh | grep -c FINDING   # 0
grep -rn -i cors ../../deploy      # nothing

Results at time of writing

  • go vet, go test -race: pass (3 packages).
  • smoke.sh: 0 findings.
  • deploy/: no CORS reference to clean up.

How it was built

Implemented by a DeepSeek run scoped (Landlock) to services/gateway_dev; reviewed and finished by Claude (README line reflow, docs/05 edits outside that scope). Run log: 35 s, ~2.7k output tokens.