Add the four settings the README documented but pixa lacked (closes #61) #142
@@ -611,7 +611,10 @@ func (c *Config) validate() error {
|
||||
// validateAccessControlAllowOrigin checks that access_control_allow_origin
|
||||
// is "*" or one origin, a scheme and host with nothing after them, as
|
||||
// browsers send it in the Origin header. Anything else, such as a bare
|
||||
// hostname or a trailing slash, would match no request.
|
||||
// hostname or a trailing slash, would match no request. An origin with a
|
||||
// "*" inside, such as https://*example.com, is refused because the CORS
|
||||
// middleware reads that "*" as a pattern and would let other sites read
|
||||
// responses.
|
||||
func (c *Config) validateAccessControlAllowOrigin() error {
|
||||
origin := c.AccessControlAllowOrigin
|
||||
if origin == "*" {
|
||||
@@ -619,7 +622,8 @@ func (c *Config) validateAccessControlAllowOrigin() error {
|
||||
}
|
||||
|
||||
parsed, err := url.Parse(origin)
|
||||
if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin {
|
||||
if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin ||
|
||||
strings.Contains(origin, "*") {
|
||||
return fmt.Errorf("%s: value %q is %w",
|
||||
settingName(keyAccessControlAllowOrigin), origin, errNotAnOrigin)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user