Accept only an origin written exactly as a browser sends it (closes #61)
check / check (push) Successful in 2m36s
check / check (push) Successful in 2m36s
access_control_allow_origin is now "*", or http or https, a host that is an IP address as net/netip writes it (IPv6 in brackets) or a lowercase host name whose last part contains a letter, and an optional port 1-65535 with no leading zero that is not the scheme's default. The value must equal the origin rebuilt from those parts; anything else aborts startup naming the key, its variable and the value. README.md and config.example.yml say an origin is scheme, host and optional port, exactly as the browser sends it. Model: opus-5-5
This commit is contained in:
@@ -38,9 +38,9 @@ exhaustion
|
||||
server's write timeout and the per-request timeout); each has a
|
||||
`PIXA_` variable; durations are positive Go duration strings, the size a
|
||||
whole number of bytes up to 1 GiB, the origin `*` or one scheme, host
|
||||
name or IP address and optional port; an invalid value aborts startup
|
||||
naming the key and the value; documented in `config.example.yml` and
|
||||
`README.md`.
|
||||
and optional port, exactly as the browser sends it; an invalid value
|
||||
aborts startup naming the key and the value; documented in
|
||||
`config.example.yml` and `README.md`.
|
||||
- 2026-09-28 refuse an unparseable `exp` on `/v1/image/` and log swallowed
|
||||
cache errors (closes #72): an `exp` in the URL that is not a whole
|
||||
number, an empty `exp=` included, is a 400 naming `exp` and the value,
|
||||
|
||||
Reference in New Issue
Block a user