fix(web): mw.CORS rejects wildcard; fix README fences; align to v1.1.2
This commit is contained in:
+17
-1
@@ -6,6 +6,22 @@ This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## [1.1.2] — 2026-08-08
|
||||||
|
|
||||||
|
Patch — CORS wildcard hardening plus documentation fixes.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- **`mw.CORS` now rejects `"*"` (panics at construction)** instead of silently no-op'ing it.
|
||||||
|
`"*"` matched nothing (exact-match only), so a service passing it ran with CORS effectively
|
||||||
|
off — a silent trap. Fail loud at boot; use `mw.CORSAllowAll()` (development) or list explicit origins.
|
||||||
|
- Bumped `contracts`, `core` to v1.1.2.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- README Go examples now compile: `mw.Recover(logger)`, `health.NewHandler(...).ServeHTTP`, and the
|
||||||
|
`mw.CORS` example no longer passes `"*"`. Corrected the `CORSAllowAll` description.
|
||||||
|
|
||||||
## [1.1.1] — 2026-08-07
|
## [1.1.1] — 2026-08-07
|
||||||
|
|
||||||
Patch — coordinated framework version alignment.
|
Patch — coordinated framework version alignment.
|
||||||
@@ -69,7 +85,7 @@ Coordinated framework release. Documentation fixes plus the framework version bu
|
|||||||
request logging: method, path, status, latency; uses `StatusRecorder` to capture code
|
request logging: method, path, status, latency; uses `StatusRecorder` to capture code
|
||||||
- `CORS(origins []string) func(http.Handler) http.Handler` — sets
|
- `CORS(origins []string) func(http.Handler) http.Handler` — sets
|
||||||
`Access-Control-Allow-Origin` for listed origins; supports preflight (`OPTIONS`)
|
`Access-Control-Allow-Origin` for listed origins; supports preflight (`OPTIONS`)
|
||||||
- `CORSAllowAll() func(http.Handler) http.Handler` — shorthand for `CORS([]string{"*"})`
|
- `CORSAllowAll() func(http.Handler) http.Handler` — allows any origin by reflecting the request `Origin` (no `Access-Control-Allow-Credentials`); development only
|
||||||
- `RateLimiterStore` interface — `Allow(ctx context.Context, key string) (bool, error)`;
|
- `RateLimiterStore` interface — `Allow(ctx context.Context, key string) (bool, error)`;
|
||||||
pluggable backend; `error` return allows infrastructure failures to surface; fail-open
|
pluggable backend; `error` return allows infrastructure failures to surface; fail-open
|
||||||
contract: non-nil error allows the request
|
contract: non-nil error allows the request
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# einherjar/web
|
# einherjar/web
|
||||||
|
|
||||||
[](https://code.nochebuena.dev/einherjar/web)
|
[](https://code.nochebuena.dev/einherjar/web)
|
||||||
[](LICENSE)
|
[](LICENSE)
|
||||||
[](https://go.dev)
|
[](https://go.dev)
|
||||||
|
|
||||||
@@ -46,7 +46,7 @@ logger := logz.New(logz.Config{JSON: true, StaticArgs: []any{"service", "api"}})
|
|||||||
srv := web.New(logger)
|
srv := web.New(logger)
|
||||||
// Pre-wired stack: Recover → RequestID (UUID v7/v4) → RequestLogger → [CORS]
|
// Pre-wired stack: Recover → RequestID (UUID v7/v4) → RequestLogger → [CORS]
|
||||||
|
|
||||||
srv.Get("/health", health.NewHandler(logger, db, cache))
|
srv.Get("/health", health.NewHandler(logger, db, cache).ServeHTTP)
|
||||||
|
|
||||||
lc := launcher.New(logger)
|
lc := launcher.New(logger)
|
||||||
lc.Append(srv)
|
lc.Append(srv)
|
||||||
@@ -76,7 +76,7 @@ Environment variables for `web.New`:
|
|||||||
| `EINHERJAR_SERVER_WRITE_TIMEOUT` | `10s` | HTTP write timeout |
|
| `EINHERJAR_SERVER_WRITE_TIMEOUT` | `10s` | HTTP write timeout |
|
||||||
| `EINHERJAR_SERVER_IDLE_TIMEOUT` | `120s` | Keep-alive idle timeout |
|
| `EINHERJAR_SERVER_IDLE_TIMEOUT` | `120s` | Keep-alive idle timeout |
|
||||||
| `EINHERJAR_SERVER_SHUTDOWN_TIMEOUT` | `10s` | Graceful shutdown budget |
|
| `EINHERJAR_SERVER_SHUTDOWN_TIMEOUT` | `10s` | Graceful shutdown budget |
|
||||||
| `EINHERJAR_SERVER_CORS_ORIGINS` | _(empty — CORS off)_ | Comma-separated allowed origins |
|
| `EINHERJAR_SERVER_CORS_ORIGINS` | _(empty — CORS off)_ | Comma-separated allowed origins (`*` is rejected — use `mw.CORSAllowAll()` in code for allow-all) |
|
||||||
|
|
||||||
### Tier 2 — Full control (`server.New`)
|
### Tier 2 — Full control (`server.New`)
|
||||||
|
|
||||||
@@ -90,9 +90,9 @@ import (
|
|||||||
|
|
||||||
srv := server.New(logger, server.Config{Port: 9090},
|
srv := server.New(logger, server.Config{Port: 9090},
|
||||||
server.WithMiddleware(
|
server.WithMiddleware(
|
||||||
mw.Recover(),
|
mw.Recover(logger),
|
||||||
mw.RequestID(myIDGenerator),
|
mw.RequestID(myIDGenerator),
|
||||||
mw.CORS([]string{"*"}),
|
mw.CORS([]string{"https://example.com"}),
|
||||||
mw.RequestLogger(logger),
|
mw.RequestLogger(logger),
|
||||||
myOwnMiddleware,
|
myOwnMiddleware,
|
||||||
),
|
),
|
||||||
@@ -177,7 +177,7 @@ values are mapped to their canonical HTTP status codes (full 16-code table below
|
|||||||
import "code.nochebuena.dev/einherjar/web/health"
|
import "code.nochebuena.dev/einherjar/web/health"
|
||||||
|
|
||||||
// db and cache implement observability.Checkable
|
// db and cache implement observability.Checkable
|
||||||
srv.Get("/health", health.NewHandler(logger, db, cache))
|
srv.Get("/health", health.NewHandler(logger, db, cache).ServeHTTP)
|
||||||
|
|
||||||
// Response shape:
|
// Response shape:
|
||||||
// {"status":"UP","components":{"db":{"status":"UP","latency":"1.2ms"}}}
|
// {"status":"UP","components":{"db":{"status":"UP","latency":"1.2ms"}}}
|
||||||
|
|||||||
@@ -3,8 +3,8 @@ module code.nochebuena.dev/einherjar/web
|
|||||||
go 1.26
|
go 1.26
|
||||||
|
|
||||||
require (
|
require (
|
||||||
code.nochebuena.dev/einherjar/contracts v1.1.1
|
code.nochebuena.dev/einherjar/contracts v1.1.2
|
||||||
code.nochebuena.dev/einherjar/core v1.1.1
|
code.nochebuena.dev/einherjar/core v1.1.2
|
||||||
github.com/go-chi/chi/v5 v5.2.1
|
github.com/go-chi/chi/v5 v5.2.1
|
||||||
github.com/google/uuid v1.6.0
|
github.com/google/uuid v1.6.0
|
||||||
golang.org/x/time v0.11.0
|
golang.org/x/time v0.11.0
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
code.nochebuena.dev/einherjar/contracts v1.1.1 h1:MRQUR8Q1D4wIOUIz11vpAdsapWqFTMwr0/VRvWbGO3s=
|
code.nochebuena.dev/einherjar/contracts v1.1.2 h1:LNAFCKQjpNjkCyMid2AgkhDPPzOx8dvpRqqZ7F3zpo0=
|
||||||
code.nochebuena.dev/einherjar/contracts v1.1.1/go.mod h1:ccltUtrFb5+MEJdkx2VVEUL+xC5pupVlVVsMM8AlCWI=
|
code.nochebuena.dev/einherjar/contracts v1.1.2/go.mod h1:ccltUtrFb5+MEJdkx2VVEUL+xC5pupVlVVsMM8AlCWI=
|
||||||
code.nochebuena.dev/einherjar/core v1.1.1 h1:W6V/Peh1ffWjqZnBuBQLn4UGM+bgvWt9MQuktTEfDFw=
|
code.nochebuena.dev/einherjar/core v1.1.2 h1:iYU2fIWtnyOYFbTMD92NaLJMye4XgZHXWhEjB3iS7lo=
|
||||||
code.nochebuena.dev/einherjar/core v1.1.1/go.mod h1:ninuZlnO178zC4rOdt5vjGojnlOpygP8cDorrecAeTY=
|
code.nochebuena.dev/einherjar/core v1.1.2/go.mod h1:Y7qZ9nri9Ydey3+40yz75KErOvOUjRSoffdykXbncsw=
|
||||||
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
||||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
github.com/gabriel-vasile/mimetype v1.4.12 h1:e9hWvmLYvtp846tLHam2o++qitpguFiYCKbn0w9jyqw=
|
github.com/gabriel-vasile/mimetype v1.4.12 h1:e9hWvmLYvtp846tLHam2o++qitpguFiYCKbn0w9jyqw=
|
||||||
|
|||||||
@@ -11,6 +11,15 @@ const (
|
|||||||
// Returns 204 No Content for OPTIONS preflight requests.
|
// Returns 204 No Content for OPTIONS preflight requests.
|
||||||
// Pass the outermost origins first; an empty slice is a no-op.
|
// Pass the outermost origins first; an empty slice is a no-op.
|
||||||
func CORS(origins []string) func(http.Handler) http.Handler {
|
func CORS(origins []string) func(http.Handler) http.Handler {
|
||||||
|
// "*" is a silent no-op here (exact-match only) — reject it loudly at
|
||||||
|
// construction so a misconfigured service fails to boot instead of quietly
|
||||||
|
// blocking every browser. For allow-all, call CORSAllowAll (development only).
|
||||||
|
for _, o := range origins {
|
||||||
|
if o == "*" {
|
||||||
|
panic(`mw.CORS: "*" is not a valid origin — list explicit origins, or use CORSAllowAll() for allow-all`)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
originSet := make(map[string]struct{}, len(origins))
|
originSet := make(map[string]struct{}, len(origins))
|
||||||
for _, o := range origins {
|
for _, o := range origins {
|
||||||
originSet[o] = struct{}{}
|
originSet[o] = struct{}{}
|
||||||
|
|||||||
Reference in New Issue
Block a user