Skip to content

Add an opt-out CORS proxy toggle to ZeitHawk - #7

Merged
BruceLittle merged 1 commit into
mainfrom
claude/stoic-archimedes-qnrnxl
Sep 17, 2026
Merged

BruceLittle merged 1 commit into
mainfrom
claude/stoic-archimedes-qnrnxl

Conversation

@BruceLittle

Copy link
Copy Markdown
Owner

Summary

  • Adds a toggle in ZeitHawk's header (on by default) that routes Repeater, Intruder, Recon's DNS/RDAP lookups, and Vuln Scan through the public proxy corsproxy.io, so requests reach targets that would otherwise block cross-origin access entirely
  • The toggle's state persists per-browser via localStorage; turning it off reverts every proxied request back to a direct fetch()
  • Recon's HTTP-reachability check is deliberately not proxied — it already uses mode:'no-cors', which isn't blocked by CORS in the first place, so routing it through a proxy would only change the network vantage point, not fix anything
  • Vuln Scan's honest three-state header model (Present / Not readable cross-origin — never a false "Missing") is unchanged by this: whether corsproxy.io itself exposes a target's original headers via Access-Control-Expose-Headers isn't something this page can verify, so the same conservative claim applies whether the proxy is on or off
  • Updates tools/zeithawk/README.md with a new section documenting the toggle, its third-party tradeoff, and why the port-reachability check is exempt

Test plan

  • Verified with Playwright: proxy is on by default, and a Repeater request correctly routes through https://corsproxy.io/?url=... rather than hitting the target directly
  • Verified toggling off correctly reverts to a direct request to the target, and the on-screen status label updates
  • Full regression pass across all seven tabs (Repeater, Intruder, Decoder, Comparer, History, Recon, Vuln Scan) with mocked network responses — all tabs render, no console/page errors
  • Manually verify against a real CORS-restricted target in an unrestricted browser (this sandbox's own proxy blocks corsproxy.io itself, so live end-to-end behavior against a real target needs testing outside this environment)

🤖 Generated with Claude Code

https://claude.ai/code/session_01SkupxCaLk9Nnq24YhigdAn


Generated by Claude Code

Adds a header toggle (on by default) that routes Repeater, Intruder,
Recon's DNS/RDAP lookups, and Vuln Scan through corsproxy.io, so requests
succeed against targets that don't set their own permissive CORS headers.
State persists in localStorage. Recon's port-reachability check is left
unproxied since it already uses mode:'no-cors', which isn't CORS-blocked
in the first place.

Vuln Scan's header checks keep their honest three-state model regardless
of the toggle: a header is only ever reported "Present" when actually
read, never inferred "Missing" from silence, since what the proxy itself
exposes via Access-Control-Expose-Headers isn't something this page can
verify.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SkupxCaLk9Nnq24YhigdAn
@BruceLittle
BruceLittle merged commit e4e5d0c into main Sep 17, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants