Send CORS headers only from the image routes (closes #98)
check / check (push) Successful in 5m49s
check / check (push) Successful in 5m49s
The CORS middleware, with the access_control_allow_origin origin, moved from the router root onto a /v1 subrouter holding /v1/image/ and /v1/e/. The login and URL generator pages, /metrics, the health check, robots.txt and /static/ no longer send Access-Control-Allow-Origin, so their safety no longer rests on the CORS options chosen for the image routes. It is a subrouter rather than a route group because a group's middleware runs only for a request that matches one of its routes, and a preflight OPTIONS request matches none. The maintenance mode group moved inside it unchanged. README.md and config.example.yml say the setting covers the image routes only. Model: opus-5-5
This commit is contained in:
@@ -29,6 +29,12 @@ P2: security: referer blacklist
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29 only the image routes send CORS headers (closes #98): the CORS
|
||||
middleware, with the `access_control_allow_origin` origin, moved from the
|
||||
router root onto a `/v1` subrouter holding `/v1/image/` and `/v1/e/`, where it
|
||||
still answers a preflight `OPTIONS` request; the login and URL generator
|
||||
pages, `/metrics` and the other routes send no `Access-Control-Allow-Origin`;
|
||||
documented in `README.md` and `config.example.yml`.
|
||||
- 2026-10-02 a plain `docker build .` stamps the tag or short commit, not
|
||||
`dev` (closes #166): `.dockerignore` lets `.git` into the build context,
|
||||
without `.git/config`; with no `VERSION` build argument the `Dockerfile`
|
||||
|
||||
Reference in New Issue
Block a user