State the origin rule in README.md and config.example.yml (closes #61)
check / check (push) Successful in 3m4s

Both now say what access_control_allow_origin accepts, instead of
"exactly as the browser sends it", and that another scheme, such as a
browser extension's, aborts startup.

Model: opus-5-5
This commit is contained in:
2026-09-28 20:43:49 +00:00
parent 5e335fbe63
commit 741c4f71a0
3 changed files with 14 additions and 7 deletions
+6 -3
View File
@@ -200,9 +200,12 @@ Key settings in more detail:
- `access_control_allow_origin` — the origin a browser lets read pixa's
responses, sent as the CORS `Access-Control-Allow-Origin` header: `*`, the
default, is any site; otherwise one origin: scheme, host and optional port,
exactly as the browser sends it, such as `https://example.com`. Anything
else aborts startup
default, is any site; otherwise one `http` or `https` origin such as
`https://example.com`, whose host is a lowercase host name (letters,
digits, hyphens and dots, with a letter in its last part) or an IP address
(IPv6 in brackets, in its shortest form), with an optional port 1-65535
that has no leading zero and is not the scheme's default. Any other value,
including another scheme such as a browser extension's, aborts startup
- `allowlist_hosts` — list of allowed upstream hosts
- `blocked_networks` — list of CIDR ranges to refuse for SSRF protection,
added to the always-enforced built-in ranges (loopback, private,