Send CORS headers only from the image routes (closes #98)
check / check (push) Waiting to run
check / check (push) Waiting to run
The CORS middleware, with the access_control_allow_origin origin, moved from the router root onto a /v1 subrouter holding /v1/image/ and /v1/e/. The login and URL generator pages, /metrics, the health check, robots.txt and /static/ no longer send Access-Control-Allow-Origin, so their safety no longer rests on the CORS options chosen for the image routes. It is a subrouter rather than a route group because a group's middleware runs only for a request that matches one of its routes, and a preflight OPTIONS request matches none. The maintenance mode group moved inside it unchanged. README.md and config.example.yml say the setting covers the image routes only. Model: opus-5-5
This commit is contained in:
@@ -29,6 +29,12 @@ P2: security: referer blacklist
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29 only the image routes send CORS headers (closes #98): the CORS
|
||||
middleware, with the `access_control_allow_origin` origin, moved from the
|
||||
router root onto a `/v1` subrouter holding `/v1/image/` and `/v1/e/`, where it
|
||||
still answers a preflight `OPTIONS` request; the login and URL generator
|
||||
pages, `/metrics` and the other routes send no `Access-Control-Allow-Origin`;
|
||||
documented in `README.md` and `config.example.yml`.
|
||||
- 2026-09-29 the container makes `/var/lib/pixa` usable by itself (closes
|
||||
#159): `deploy/docker-entrypoint.sh` creates the directory if it is missing,
|
||||
gives the directory and everything in it to `pixad` when the directory or one
|
||||
|
||||
Reference in New Issue
Block a user