State the origin rule in README.md and config.example.yml (closes #61)

Both now say what access_control_allow_origin accepts, instead of
"exactly as the browser sends it", and that another scheme, such as a
browser extension's, aborts startup.

Model: opus-5-5
This commit is contained in:
2026-09-29 06:12:11 +00:00
parent 014de9c87f
commit d2dfd6e58a
3 changed files with 14 additions and 7 deletions
+6 -2
View File
@@ -84,8 +84,12 @@ downstream_timeout: 60s
# The origin a browser lets read pixa's responses, sent as the CORS
# Access-Control-Allow-Origin header: "*" (the default) is any site;
# otherwise one origin: scheme, host and optional port, exactly as the
# browser sends it, such as https://example.com
# otherwise one http or https origin such as https://example.com, whose
# host is a lowercase host name (letters, digits, hyphens and dots, with a
# letter in its last part) or an IP address (IPv6 in brackets, in its
# shortest form), with an optional port 1-65535 that has no leading zero
# and is not the scheme's default. Any other value, including another
# scheme such as a browser extension's, aborts startup.
access_control_allow_origin: "*"
# Maximum disk cache size in bytes. Explicit values are used exactly as