Send CORS headers only from the image routes (closes #98) #162

Open
clawbot wants to merge 2 commits from issue-98-cors-image-routes-only into next
Collaborator

Closes #98; builds on the origin setting from #61.

The CORS middleware, with the access_control_allow_origin origin, wrapped every route from the router root, so the login and URL generator pages and /metrics sent Access-Control-Allow-Origin too, and their safety rested on CORS options chosen for the image routes. It now wraps only /v1/image/ and /v1/e/. /metrics gets no CORS headers: a metrics scraper reads it with basic auth, and no page on another site has a reason to.

A new test sends requests through the server's routes and checks the header on both image routes, a preflight included, and its absence on /, /generate and /logout. README.md and config.example.yml say the setting covers the image routes only.

Worth knowing:

  • The image routes are a /v1 subrouter, not a route group: a group's middleware runs only for a request matching one of its routes, and a preflight OPTIONS request matches none. The maintenance mode group moved inside it unchanged; the paths are now written /image/* and /e/{token}/*.
  • The health check, robots.txt and /static/ also stop sending the header.
  • POST /generate never got the header, as POST is not an allowed CORS method; its test case guards against that list growing.

Disclosures:

  • Unverified by test: /metrics. Its middleware registers with the process-wide Prometheus registry, which only one test per package can do, and the maintenance test already does.
  • Judgement call: the maintenance tests' encrypted image path is now a named constant shared with the new test, for the linter's repeated-string check; what they check is unchanged.
  • Left as is: the generic example in CONVENTIONS.md still applies CORS at the router root.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/pixa/issues/98; builds on the origin setting from https://git.eeqj.de/sneak/pixa/issues/61. The CORS middleware, with the `access_control_allow_origin` origin, wrapped every route from the router root, so the login and URL generator pages and `/metrics` sent `Access-Control-Allow-Origin` too, and their safety rested on CORS options chosen for the image routes. It now wraps only `/v1/image/` and `/v1/e/`. `/metrics` gets no CORS headers: a metrics scraper reads it with basic auth, and no page on another site has a reason to. A new test sends requests through the server's routes and checks the header on both image routes, a preflight included, and its absence on `/`, `/generate` and `/logout`. `README.md` and `config.example.yml` say the setting covers the image routes only. Worth knowing: - The image routes are a `/v1` subrouter, not a route group: a group's middleware runs only for a request matching one of its routes, and a preflight `OPTIONS` request matches none. The maintenance mode group moved inside it unchanged; the paths are now written `/image/*` and `/e/{token}/*`. - The health check, `robots.txt` and `/static/` also stop sending the header. - `POST /generate` never got the header, as `POST` is not an allowed CORS method; its test case guards against that list growing. Disclosures: - Unverified by test: `/metrics`. Its middleware registers with the process-wide Prometheus registry, which only one test per package can do, and the maintenance test already does. - Judgement call: the maintenance tests' encrypted image path is now a named constant shared with the new test, for the linter's repeated-string check; what they check is unchanged. - Left as is: the generic example in `CONVENTIONS.md` still applies CORS at the router root. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 13:01:47 +02:00
clawbot self-assigned this 2026-09-29 13:01:47 +02:00
clawbot added 2 commits 2026-09-29 13:01:48 +02:00
A new server test sends requests with an Origin header through the
server's routes and expects Access-Control-Allow-Origin, set to the
configured origin, on both image routes, a preflight OPTIONS request
included, and no such header on the login and URL generator pages.
It fails for now: the CORS middleware still wraps every route.

The encrypted image path the maintenance tests use is now a named
constant, shared with the new test; what they check is unchanged.

Model: opus-5-5
The CORS middleware, with the access_control_allow_origin origin, moved
from the router root onto a /v1 subrouter holding /v1/image/ and /v1/e/.
The login and URL generator pages, /metrics, the health check,
robots.txt and /static/ no longer send Access-Control-Allow-Origin, so
their safety no longer rests on the CORS options chosen for the image
routes.

It is a subrouter rather than a route group because a group's
middleware runs only for a request that matches one of its routes, and
a preflight OPTIONS request matches none. The maintenance mode group
moved inside it unchanged.

README.md and config.example.yml say the setting covers the image
routes only.

Model: opus-5-5
Some checks are pending
check / check (push) Waiting to run
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-98-cors-image-routes-only:issue-98-cors-image-routes-only
git checkout issue-98-cors-image-routes-only
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#162