Source: RepoLens Security-Audit 2026-08-16 (findings security/security-headers/001–006, adversarial-verified ✅)
superpowers-brainstorming companion server.cjs + live-data-server.py:
- Missing
X-Content-Type-Options: nosniff
Access-Control-Allow-Origin: * on every /api/* route (live-data-server.py)
- CSP only restricts
frame-ancestors — user-authored HTML can exfiltrate
- Docs (
sse-v2-architecture.md) prescribe * as required pattern
Suggested fix: central header helper (nosniff + restrictive CORS + full CSP), fix the doc pattern, add tests.
Source: RepoLens Security-Audit 2026-08-16 (findings
security/security-headers/001–006, adversarial-verified ✅)superpowers-brainstormingcompanionserver.cjs+live-data-server.py:X-Content-Type-Options: nosniffAccess-Control-Allow-Origin: *on every/api/*route (live-data-server.py)frame-ancestors— user-authored HTML can exfiltratesse-v2-architecture.md) prescribe*as required patternSuggested fix: central header helper (nosniff + restrictive CORS + full CSP), fix the doc pattern, add tests.