Refuse OPTIONS * like any other API request (closes #4)
check / check (push) Successful in 1m16s
check / check (push) Successful in 1m16s
net/http answered "OPTIONS *" itself, with 200, before the router, so it skipped the credential check and the security headers. The server now passes it to the router, which refuses it with 401 like any other request without the credential. A test sends it to a running server, since the handler alone never sees it. Model: opus-5-5
This commit is contained in:
@@ -95,6 +95,9 @@ func New(p Params) *http.Server {
|
||||
ReadTimeout: readTimeout,
|
||||
WriteTimeout: writeTimeout,
|
||||
IdleTimeout: idleTimeout,
|
||||
// Otherwise net/http answers "OPTIONS *" itself, with 200 and
|
||||
// without the credential check or the headers.
|
||||
DisableGeneralOptionsHandler: true,
|
||||
// net/http's own messages, such as a handler's panic, go to the
|
||||
// same JSON log as everything else.
|
||||
ErrorLog: slog.NewLogLogger(p.Log.Handler(), slog.LevelError),
|
||||
|
||||
Reference in New Issue
Block a user