Send CORS headers only from the image routes (closes #98)
check / check (push) Waiting to run
check / check (push) Waiting to run
The CORS middleware, with the access_control_allow_origin origin, moved from the router root onto a /v1 subrouter holding /v1/image/ and /v1/e/. The login and URL generator pages, /metrics, the health check, robots.txt and /static/ no longer send Access-Control-Allow-Origin, so their safety no longer rests on the CORS options chosen for the image routes. It is a subrouter rather than a route group because a group's middleware runs only for a request that matches one of its routes, and a preflight OPTIONS request matches none. The maintenance mode group moved inside it unchanged. README.md and config.example.yml say the setting covers the image routes only. Model: opus-5-5
This commit is contained in:
+3
-2
@@ -103,8 +103,9 @@ upstream_max_response_size: 52428800
|
||||
# longer than upstream_fetch_timeout plus 20 seconds.
|
||||
downstream_timeout: 60s
|
||||
|
||||
# The origin a browser lets read pixa's responses, sent as the CORS
|
||||
# Access-Control-Allow-Origin header: "*" (the default) is any site;
|
||||
# The origin a browser lets read the responses of the image routes,
|
||||
# /v1/image/ and /v1/e/, sent as the CORS Access-Control-Allow-Origin
|
||||
# header; no other route sends it. "*" (the default) is any site;
|
||||
# otherwise one http or https origin such as https://example.com, whose
|
||||
# host is a lowercase host name (letters, digits, hyphens and dots, with a
|
||||
# letter in its last part) or an IP address (IPv6 in brackets, in its
|
||||
|
||||
Reference in New Issue
Block a user