State the origin rule in README.md and config.example.yml (closes #61)

Both now say what access_control_allow_origin accepts, instead of
"exactly as the browser sends it", and that another scheme, such as a
browser extension's, aborts startup.

Model: opus-5-5
This commit is contained in:
2026-09-29 06:12:11 +00:00
parent 014de9c87f
commit d2dfd6e58a
3 changed files with 14 additions and 7 deletions
+2 -2
View File
@@ -64,8 +64,8 @@ exhaustion
(default 50 MiB) and `downstream_timeout` (default `60s`, both the
server's write timeout and the per-request timeout); each has a
`PIXA_` variable; durations are positive Go duration strings, the size a
whole number of bytes up to 1 GiB, the origin `*` or one scheme, host
and optional port, exactly as the browser sends it; an invalid value
whole number of bytes up to 1 GiB, the origin `*` or one `http` or
`https` origin as `README.md` describes it; an invalid value
aborts startup naming the key and the value; documented in
`config.example.yml` and `README.md`.
- 2026-09-28 cache stats report real numbers (closes #56): `Cache.Stats`