Add the four settings the README documented but pixa lacked (closes #61) #142

Merged
clawbot merged 12 commits from issue-61-config-keys into next 2026-09-29 08:49:19 +02:00
3 changed files with 14 additions and 7 deletions
Showing only changes of commit d2dfd6e58a - Show all commits
+6 -3
View File
@@ -249,9 +249,12 @@ Key settings in more detail:
- `access_control_allow_origin` — the origin a browser lets read pixa's - `access_control_allow_origin` — the origin a browser lets read pixa's
responses, sent as the CORS `Access-Control-Allow-Origin` header: `*`, the responses, sent as the CORS `Access-Control-Allow-Origin` header: `*`, the
default, is any site; otherwise one origin: scheme, host and optional port, default, is any site; otherwise one `http` or `https` origin such as
exactly as the browser sends it, such as `https://example.com`. Anything `https://example.com`, whose host is a lowercase host name (letters,
else aborts startup digits, hyphens and dots, with a letter in its last part) or an IP address
(IPv6 in brackets, in its shortest form), with an optional port 1-65535
that has no leading zero and is not the scheme's default. Any other value,
including another scheme such as a browser extension's, aborts startup
- `allowlist_hosts` — list of allowed upstream hosts - `allowlist_hosts` — list of allowed upstream hosts
- `blocked_networks` — list of CIDR ranges to refuse for SSRF protection, - `blocked_networks` — list of CIDR ranges to refuse for SSRF protection,
added to the always-enforced built-in ranges (loopback, private, added to the always-enforced built-in ranges (loopback, private,
+2 -2
View File
@@ -64,8 +64,8 @@ exhaustion
(default 50 MiB) and `downstream_timeout` (default `60s`, both the (default 50 MiB) and `downstream_timeout` (default `60s`, both the
server's write timeout and the per-request timeout); each has a server's write timeout and the per-request timeout); each has a
`PIXA_` variable; durations are positive Go duration strings, the size a `PIXA_` variable; durations are positive Go duration strings, the size a
whole number of bytes up to 1 GiB, the origin `*` or one scheme, host whole number of bytes up to 1 GiB, the origin `*` or one `http` or
and optional port, exactly as the browser sends it; an invalid value `https` origin as `README.md` describes it; an invalid value
aborts startup naming the key and the value; documented in aborts startup naming the key and the value; documented in
`config.example.yml` and `README.md`. `config.example.yml` and `README.md`.
- 2026-09-28 cache stats report real numbers (closes #56): `Cache.Stats` - 2026-09-28 cache stats report real numbers (closes #56): `Cache.Stats`
+6 -2
View File
@@ -84,8 +84,12 @@ downstream_timeout: 60s
# The origin a browser lets read pixa's responses, sent as the CORS # The origin a browser lets read pixa's responses, sent as the CORS
# Access-Control-Allow-Origin header: "*" (the default) is any site; # Access-Control-Allow-Origin header: "*" (the default) is any site;
# otherwise one origin: scheme, host and optional port, exactly as the # otherwise one http or https origin such as https://example.com, whose
# browser sends it, such as https://example.com # host is a lowercase host name (letters, digits, hyphens and dots, with a
# letter in its last part) or an IP address (IPv6 in brackets, in its
# shortest form), with an optional port 1-65535 that has no leading zero
# and is not the scheme's default. Any other value, including another
# scheme such as a browser extension's, aborts startup.
access_control_allow_origin: "*" access_control_allow_origin: "*"
# Maximum disk cache size in bytes. Explicit values are used exactly as # Maximum disk cache size in bytes. Explicit values are used exactly as