check / check (push) Successful in 4m2s
An unset WEBHOOKER_ENVIRONMENT now resolves to prod rather than dev, so an operator who forgets the variable is not silently permissive. The only behaviour dev still changes is the CORS middleware, which answers every origin with Access-Control-Allow-Origin: *; that is now off unless dev is set explicitly. Cookie Secure and CSRF strictness are decided per request from the transport and are unaffected. Updated resolveEnvironment and its comment, the README configuration table and prose, and tests covering the default and the explicit dev. Comments that justified behaviour by the old dev default (the TRUSTED_PROXIES warning, a CSRF test) were corrected; that warning still fires in every environment when TRUSTED_PROXIES is empty. Model: opus-4-8