check / check (push) Failing after 1m56s
A new server test sends requests with an Origin header through the server's routes and expects Access-Control-Allow-Origin, set to the configured origin, on both image routes, a preflight OPTIONS request included, and no such header on the login and URL generator pages. It fails for now: the CORS middleware still wraps every route. The encrypted image path the maintenance tests use is now a named constant, shared with the new test; what they check is unchanged. Model: opus-5-5