Accept only an origin written exactly as a browser sends it (closes #61)
check / check (push) Successful in 2m36s

access_control_allow_origin is now "*", or http or https, a host that is
an IP address as net/netip writes it (IPv6 in brackets) or a lowercase
host name whose last part contains a letter, and an optional port 1-65535
with no leading zero that is not the scheme's default. The value must
equal the origin rebuilt from those parts; anything else aborts startup
naming the key, its variable and the value. README.md and
config.example.yml say an origin is scheme, host and optional port,
exactly as the browser sends it.

Model: opus-5-5
This commit is contained in:
2026-09-28 20:25:42 +00:00
parent 37372cd6fe
commit 1d707c9768
4 changed files with 43 additions and 41 deletions
+3 -2
View File
@@ -200,8 +200,9 @@ Key settings in more detail:
- `access_control_allow_origin` — the origin a browser lets read pixa's
responses, sent as the CORS `Access-Control-Allow-Origin` header: `*`, the
default, is any site; otherwise one origin, scheme and host only, such as
`https://example.com`. Anything else aborts startup
default, is any site; otherwise one origin: scheme, host and optional port,
exactly as the browser sends it, such as `https://example.com`. Anything
else aborts startup
- `allowlist_hosts` — list of allowed upstream hosts
- `blocked_networks` — list of CIDR ranges to refuse for SSRF protection,
added to the always-enforced built-in ranges (loopback, private,