Diagnose CORS Policy
diagnose_cors_policyAnalyze CORS HTTP request and response headers for wildcard/credential security violations, missing Vary: Origin, preflight OPTIONS handling, and header exposure.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| request_origin | Yes | The incoming HTTP request Origin header (e.g. "https://app.example.com"). | |
| response_headers | Yes | The server HTTP response headers (as key-value map or list of "Header: Value" strings). | |
| with_credentials | No | Whether the cross-origin request includes cookies or authorization credentials. |