| 342 | // previous `[webBaseUrl]` exactly and an operator who repeats it in the env var |
| 343 | // does not get a duplicate. |
| 344 | const resolveTrustedOrigins = (webBaseUrl: string): readonly string[] => { |
| 345 | const additional = (process.env.EXECUTOR_TRUSTED_ORIGINS ?? "") |
| 346 | .split(",") |
| 347 | .map((value) => value.trim()) |
| 348 | .filter((value) => value.length > 0) |
| 349 | .map(normalizeTrustedOrigin); |
| 350 | return [...new Set([webBaseUrl, ...additional])]; |
| 351 | }; |
| 352 | |
| 353 | // The org slug doubles as a URL segment (`/<slug>/policies`), so an |
| 354 | // operator-set value must fit the shared grammar and avoid reserved root |