Refuse OPTIONS * like any other API request (closes #4)
check / check (push) Successful in 1m16s

net/http answered "OPTIONS *" itself, with 200, before the router, so
it skipped the credential check and the security headers. The server
now passes it to the router, which refuses it with 401 like any other
request without the credential. A test sends it to a running server,
since the handler alone never sees it.

Model: opus-5-5
This commit is contained in:
clawbot
2026-09-29 02:20:58 +00:00
parent 9ce902fb05
commit 0c5163e69e
2 changed files with 48 additions and 0 deletions
+3
View File
@@ -95,6 +95,9 @@ func New(p Params) *http.Server {
ReadTimeout: readTimeout,
WriteTimeout: writeTimeout,
IdleTimeout: idleTimeout,
// Otherwise net/http answers "OPTIONS *" itself, with 200 and
// without the credential check or the headers.
DisableGeneralOptionsHandler: true,
// net/http's own messages, such as a handler's panic, go to the
// same JSON log as everything else.
ErrorLog: slog.NewLogLogger(p.Log.Handler(), slog.LevelError),