Closes #98; builds on the origin setting from #61.
The CORS middleware, with the access_control_allow_origin origin, wrapped every route from the router root, so the login and URL generator pages and /metrics sent Access-Control-Allow-Origin too, and their safety rested on CORS options chosen for the image routes. It now wraps only /v1/image/ and /v1/e/. /metrics gets no CORS headers: a metrics scraper reads it with basic auth, and no page on another site has a reason to.
A new test sends requests through the server's routes and checks the header on both image routes, a preflight included, and its absence on /, /generate and /logout. README.md and config.example.yml say the setting covers the image routes only.
Worth knowing:
The image routes are a /v1 subrouter, not a route group: a group's middleware runs only for a request matching one of its routes, and a preflight OPTIONS request matches none. The maintenance mode group moved inside it unchanged; the paths are now written /image/* and /e/{token}/*.
The health check, robots.txt and /static/ also stop sending the header.
POST /generate never got the header, as POST is not an allowed CORS method; its test case guards against that list growing.
Disclosures:
Unverified by test: /metrics. Its middleware registers with the process-wide Prometheus registry, which only one test per package can do, and the maintenance test already does.
Judgement call: the maintenance tests' encrypted image path is now a named constant shared with the new test, for the linter's repeated-string check; what they check is unchanged.
Left as is: the generic example in CONVENTIONS.md still applies CORS at the router root.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/pixa/issues/98; builds on the origin setting from https://git.eeqj.de/sneak/pixa/issues/61.
The CORS middleware, with the `access_control_allow_origin` origin, wrapped every route from the router root, so the login and URL generator pages and `/metrics` sent `Access-Control-Allow-Origin` too, and their safety rested on CORS options chosen for the image routes. It now wraps only `/v1/image/` and `/v1/e/`. `/metrics` gets no CORS headers: a metrics scraper reads it with basic auth, and no page on another site has a reason to.
A new test sends requests through the server's routes and checks the header on both image routes, a preflight included, and its absence on `/`, `/generate` and `/logout`. `README.md` and `config.example.yml` say the setting covers the image routes only.
Worth knowing:
- The image routes are a `/v1` subrouter, not a route group: a group's middleware runs only for a request matching one of its routes, and a preflight `OPTIONS` request matches none. The maintenance mode group moved inside it unchanged; the paths are now written `/image/*` and `/e/{token}/*`.
- The health check, `robots.txt` and `/static/` also stop sending the header.
- `POST /generate` never got the header, as `POST` is not an allowed CORS method; its test case guards against that list growing.
Disclosures:
- Unverified by test: `/metrics`. Its middleware registers with the process-wide Prometheus registry, which only one test per package can do, and the maintenance test already does.
- Judgement call: the maintenance tests' encrypted image path is now a named constant shared with the new test, for the linter's repeated-string check; what they check is unchanged.
- Left as is: the generic example in `CONVENTIONS.md` still applies CORS at the router root.
Model: opus-5-5
A new server test sends requests with an Origin header through the
server's routes and expects Access-Control-Allow-Origin, set to the
configured origin, on both image routes, a preflight OPTIONS request
included, and no such header on the login and URL generator pages.
It fails for now: the CORS middleware still wraps every route.
The encrypted image path the maintenance tests use is now a named
constant, shared with the new test; what they check is unchanged.
Model: opus-5-5
The CORS middleware, with the access_control_allow_origin origin, moved
from the router root onto a /v1 subrouter holding /v1/image/ and /v1/e/.
The login and URL generator pages, /metrics, the health check,
robots.txt and /static/ no longer send Access-Control-Allow-Origin, so
their safety no longer rests on the CORS options chosen for the image
routes.
It is a subrouter rather than a route group because a group's
middleware runs only for a request that matches one of its routes, and
a preflight OPTIONS request matches none. The maintenance mode group
moved inside it unchanged.
README.md and config.example.yml say the setting covers the image
routes only.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #98; builds on the origin setting from #61.
The CORS middleware, with the
access_control_allow_originorigin, wrapped every route from the router root, so the login and URL generator pages and/metricssentAccess-Control-Allow-Origintoo, and their safety rested on CORS options chosen for the image routes. It now wraps only/v1/image/and/v1/e/./metricsgets no CORS headers: a metrics scraper reads it with basic auth, and no page on another site has a reason to.A new test sends requests through the server's routes and checks the header on both image routes, a preflight included, and its absence on
/,/generateand/logout.README.mdandconfig.example.ymlsay the setting covers the image routes only.Worth knowing:
/v1subrouter, not a route group: a group's middleware runs only for a request matching one of its routes, and a preflightOPTIONSrequest matches none. The maintenance mode group moved inside it unchanged; the paths are now written/image/*and/e/{token}/*.robots.txtand/static/also stop sending the header.POST /generatenever got the header, asPOSTis not an allowed CORS method; its test case guards against that list growing.Disclosures:
/metrics. Its middleware registers with the process-wide Prometheus registry, which only one test per package can do, and the maintenance test already does.CONVENTIONS.mdstill applies CORS at the router root.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.