
Whitelisting subdomain doesn't work as expected

sibsfinx opened this issue · 0 comments

I'm running cors-anywhere via pm2:

CORSANYWHERE_WHITELIST=, PORT=8080 pm2 start server.js --name cors-anywhere

when trying to reach it from a subdomain, I get 403:

const r = await fetch("", {
  "headers": {
      "origin": "",

// fails with 403
// The origin "" was not whitelisted by the operator of this proxy.

But when doing the same from a 2nd level domain, it's all good

const r = await fetch("", {
  "headers": {
      "origin": "",

// 200 OK

Am I missing anything?