diff --git a/CHANGELOG.md b/CHANGELOG.md index f42c01b..b08dd58 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,22 @@ This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html --- +## [1.1.2] — 2026-08-08 + +Patch — CORS wildcard hardening plus documentation fixes. + +### Changed + +- **`mw.CORS` now rejects `"*"` (panics at construction)** instead of silently no-op'ing it. + `"*"` matched nothing (exact-match only), so a service passing it ran with CORS effectively + off — a silent trap. Fail loud at boot; use `mw.CORSAllowAll()` (development) or list explicit origins. +- Bumped `contracts`, `core` to v1.1.2. + +### Fixed + +- README Go examples now compile: `mw.Recover(logger)`, `health.NewHandler(...).ServeHTTP`, and the + `mw.CORS` example no longer passes `"*"`. Corrected the `CORSAllowAll` description. + ## [1.1.1] — 2026-08-07 Patch — coordinated framework version alignment. @@ -69,7 +85,7 @@ Coordinated framework release. Documentation fixes plus the framework version bu request logging: method, path, status, latency; uses `StatusRecorder` to capture code - `CORS(origins []string) func(http.Handler) http.Handler` — sets `Access-Control-Allow-Origin` for listed origins; supports preflight (`OPTIONS`) -- `CORSAllowAll() func(http.Handler) http.Handler` — shorthand for `CORS([]string{"*"})` +- `CORSAllowAll() func(http.Handler) http.Handler` — allows any origin by reflecting the request `Origin` (no `Access-Control-Allow-Credentials`); development only - `RateLimiterStore` interface — `Allow(ctx context.Context, key string) (bool, error)`; pluggable backend; `error` return allows infrastructure failures to surface; fail-open contract: non-nil error allows the request diff --git a/README.md b/README.md index 69443b3..6894cad 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # einherjar/web -[![version](https://img.shields.io/badge/version-v1.1.1-5C4EE5?style=flat-square)](https://code.nochebuena.dev/einherjar/web) +[![version](https://img.shields.io/badge/version-v1.1.2-5C4EE5?style=flat-square)](https://code.nochebuena.dev/einherjar/web) [![license](https://img.shields.io/badge/license-AGPL--3.0-22863A?style=flat-square)](LICENSE) [![go](https://img.shields.io/badge/Go-1.26+-00ADD8?style=flat-square&logo=go&logoColor=white)](https://go.dev) @@ -46,7 +46,7 @@ logger := logz.New(logz.Config{JSON: true, StaticArgs: []any{"service", "api"}}) srv := web.New(logger) // Pre-wired stack: Recover → RequestID (UUID v7/v4) → RequestLogger → [CORS] -srv.Get("/health", health.NewHandler(logger, db, cache)) +srv.Get("/health", health.NewHandler(logger, db, cache).ServeHTTP) lc := launcher.New(logger) lc.Append(srv) @@ -76,7 +76,7 @@ Environment variables for `web.New`: | `EINHERJAR_SERVER_WRITE_TIMEOUT` | `10s` | HTTP write timeout | | `EINHERJAR_SERVER_IDLE_TIMEOUT` | `120s` | Keep-alive idle timeout | | `EINHERJAR_SERVER_SHUTDOWN_TIMEOUT` | `10s` | Graceful shutdown budget | -| `EINHERJAR_SERVER_CORS_ORIGINS` | _(empty — CORS off)_ | Comma-separated allowed origins | +| `EINHERJAR_SERVER_CORS_ORIGINS` | _(empty — CORS off)_ | Comma-separated allowed origins (`*` is rejected — use `mw.CORSAllowAll()` in code for allow-all) | ### Tier 2 — Full control (`server.New`) @@ -90,9 +90,9 @@ import ( srv := server.New(logger, server.Config{Port: 9090}, server.WithMiddleware( - mw.Recover(), + mw.Recover(logger), mw.RequestID(myIDGenerator), - mw.CORS([]string{"*"}), + mw.CORS([]string{"https://example.com"}), mw.RequestLogger(logger), myOwnMiddleware, ), @@ -177,7 +177,7 @@ values are mapped to their canonical HTTP status codes (full 16-code table below import "code.nochebuena.dev/einherjar/web/health" // db and cache implement observability.Checkable -srv.Get("/health", health.NewHandler(logger, db, cache)) +srv.Get("/health", health.NewHandler(logger, db, cache).ServeHTTP) // Response shape: // {"status":"UP","components":{"db":{"status":"UP","latency":"1.2ms"}}} diff --git a/go.mod b/go.mod index 25dfe58..d790fa1 100644 --- a/go.mod +++ b/go.mod @@ -3,8 +3,8 @@ module code.nochebuena.dev/einherjar/web go 1.26 require ( - code.nochebuena.dev/einherjar/contracts v1.1.1 - code.nochebuena.dev/einherjar/core v1.1.1 + code.nochebuena.dev/einherjar/contracts v1.1.2 + code.nochebuena.dev/einherjar/core v1.1.2 github.com/go-chi/chi/v5 v5.2.1 github.com/google/uuid v1.6.0 golang.org/x/time v0.11.0 diff --git a/go.sum b/go.sum index c59ec34..50bdb13 100644 --- a/go.sum +++ b/go.sum @@ -1,7 +1,7 @@ -code.nochebuena.dev/einherjar/contracts v1.1.1 h1:MRQUR8Q1D4wIOUIz11vpAdsapWqFTMwr0/VRvWbGO3s= -code.nochebuena.dev/einherjar/contracts v1.1.1/go.mod h1:ccltUtrFb5+MEJdkx2VVEUL+xC5pupVlVVsMM8AlCWI= -code.nochebuena.dev/einherjar/core v1.1.1 h1:W6V/Peh1ffWjqZnBuBQLn4UGM+bgvWt9MQuktTEfDFw= -code.nochebuena.dev/einherjar/core v1.1.1/go.mod h1:ninuZlnO178zC4rOdt5vjGojnlOpygP8cDorrecAeTY= +code.nochebuena.dev/einherjar/contracts v1.1.2 h1:LNAFCKQjpNjkCyMid2AgkhDPPzOx8dvpRqqZ7F3zpo0= +code.nochebuena.dev/einherjar/contracts v1.1.2/go.mod h1:ccltUtrFb5+MEJdkx2VVEUL+xC5pupVlVVsMM8AlCWI= +code.nochebuena.dev/einherjar/core v1.1.2 h1:iYU2fIWtnyOYFbTMD92NaLJMye4XgZHXWhEjB3iS7lo= +code.nochebuena.dev/einherjar/core v1.1.2/go.mod h1:Y7qZ9nri9Ydey3+40yz75KErOvOUjRSoffdykXbncsw= github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/gabriel-vasile/mimetype v1.4.12 h1:e9hWvmLYvtp846tLHam2o++qitpguFiYCKbn0w9jyqw= diff --git a/mw/cors.go b/mw/cors.go index e45411d..64ea96c 100644 --- a/mw/cors.go +++ b/mw/cors.go @@ -11,6 +11,15 @@ const ( // Returns 204 No Content for OPTIONS preflight requests. // Pass the outermost origins first; an empty slice is a no-op. func CORS(origins []string) func(http.Handler) http.Handler { + // "*" is a silent no-op here (exact-match only) — reject it loudly at + // construction so a misconfigured service fails to boot instead of quietly + // blocking every browser. For allow-all, call CORSAllowAll (development only). + for _, o := range origins { + if o == "*" { + panic(`mw.CORS: "*" is not a valid origin — list explicit origins, or use CORSAllowAll() for allow-all`) + } + } + originSet := make(map[string]struct{}, len(origins)) for _, o := range origins { originSet[o] = struct{}{}