From 741c4f71a00554515a21a40244c33105a5d1a1ba Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Mon, 28 Sep 2026 20:43:49 +0000 Subject: [PATCH] State the origin rule in README.md and config.example.yml (closes #61) Both now say what access_control_allow_origin accepts, instead of "exactly as the browser sends it", and that another scheme, such as a browser extension's, aborts startup. Model: opus-5-5 --- README.md | 9 ++++++--- TODO.md | 4 ++-- config.example.yml | 8 ++++++-- 3 files changed, 14 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index 28ea49c..4430629 100644 --- a/README.md +++ b/README.md @@ -200,9 +200,12 @@ Key settings in more detail: - `access_control_allow_origin` — the origin a browser lets read pixa's responses, sent as the CORS `Access-Control-Allow-Origin` header: `*`, the - default, is any site; otherwise one origin: scheme, host and optional port, - exactly as the browser sends it, such as `https://example.com`. Anything - else aborts startup + default, is any site; otherwise one `http` or `https` origin such as + `https://example.com`, whose host is a lowercase host name (letters, + digits, hyphens and dots, with a letter in its last part) or an IP address + (IPv6 in brackets, in its shortest form), with an optional port 1-65535 + that has no leading zero and is not the scheme's default. Any other value, + including another scheme such as a browser extension's, aborts startup - `allowlist_hosts` — list of allowed upstream hosts - `blocked_networks` — list of CIDR ranges to refuse for SSRF protection, added to the always-enforced built-in ranges (loopback, private, diff --git a/TODO.md b/TODO.md index a640c62..7c794ec 100644 --- a/TODO.md +++ b/TODO.md @@ -37,8 +37,8 @@ exhaustion (default 50 MiB) and `downstream_timeout` (default `60s`, both the server's write timeout and the per-request timeout); each has a `PIXA_` variable; durations are positive Go duration strings, the size a - whole number of bytes up to 1 GiB, the origin `*` or one scheme, host - and optional port, exactly as the browser sends it; an invalid value + whole number of bytes up to 1 GiB, the origin `*` or one `http` or + `https` origin as `README.md` describes it; an invalid value aborts startup naming the key and the value; documented in `config.example.yml` and `README.md`. - 2026-09-28 refuse an unparseable `exp` on `/v1/image/` and log swallowed diff --git a/config.example.yml b/config.example.yml index d86d366..c3c0a22 100644 --- a/config.example.yml +++ b/config.example.yml @@ -78,8 +78,12 @@ downstream_timeout: 60s # The origin a browser lets read pixa's responses, sent as the CORS # Access-Control-Allow-Origin header: "*" (the default) is any site; -# otherwise one origin: scheme, host and optional port, exactly as the -# browser sends it, such as https://example.com +# otherwise one http or https origin such as https://example.com, whose +# host is a lowercase host name (letters, digits, hyphens and dots, with a +# letter in its last part) or an IP address (IPv6 in brackets, in its +# shortest form), with an optional port 1-65535 that has no leading zero +# and is not the scheme's default. Any other value, including another +# scheme such as a browser extension's, aborts startup. access_control_allow_origin: "*" # Maximum disk cache size in bytes. Explicit values are used exactly as