Avoid Actix any-origin CORS with credentials enabled
`actix_cors` configurations must not combine `allow_any_origin` with `supports_credentials`.
#Metadata
#Why it matters
Wildcard origins with credentials violate browser CORS expectations and usually indicate a missing explicit origin allowlist.
#Remediation
Use `allowed_origin` with explicit HTTPS origins, or disable credentials when anonymous public access is intended.
#Repository path
The generated metadata points to critiq-rules/libs/rules/catalog/rules/rust/rust.security.actix-wildcard-cors-with-credentials.rule.yaml.