fix(web): mw.CORS rejects wildcard; fix README fences; align to v1.1.2
This commit is contained in:
+17
-1
@@ -6,6 +6,22 @@ This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html
|
||||
|
||||
---
|
||||
|
||||
## [1.1.2] — 2026-08-08
|
||||
|
||||
Patch — CORS wildcard hardening plus documentation fixes.
|
||||
|
||||
### Changed
|
||||
|
||||
- **`mw.CORS` now rejects `"*"` (panics at construction)** instead of silently no-op'ing it.
|
||||
`"*"` matched nothing (exact-match only), so a service passing it ran with CORS effectively
|
||||
off — a silent trap. Fail loud at boot; use `mw.CORSAllowAll()` (development) or list explicit origins.
|
||||
- Bumped `contracts`, `core` to v1.1.2.
|
||||
|
||||
### Fixed
|
||||
|
||||
- README Go examples now compile: `mw.Recover(logger)`, `health.NewHandler(...).ServeHTTP`, and the
|
||||
`mw.CORS` example no longer passes `"*"`. Corrected the `CORSAllowAll` description.
|
||||
|
||||
## [1.1.1] — 2026-08-07
|
||||
|
||||
Patch — coordinated framework version alignment.
|
||||
@@ -69,7 +85,7 @@ Coordinated framework release. Documentation fixes plus the framework version bu
|
||||
request logging: method, path, status, latency; uses `StatusRecorder` to capture code
|
||||
- `CORS(origins []string) func(http.Handler) http.Handler` — sets
|
||||
`Access-Control-Allow-Origin` for listed origins; supports preflight (`OPTIONS`)
|
||||
- `CORSAllowAll() func(http.Handler) http.Handler` — shorthand for `CORS([]string{"*"})`
|
||||
- `CORSAllowAll() func(http.Handler) http.Handler` — allows any origin by reflecting the request `Origin` (no `Access-Control-Allow-Credentials`); development only
|
||||
- `RateLimiterStore` interface — `Allow(ctx context.Context, key string) (bool, error)`;
|
||||
pluggable backend; `error` return allows infrastructure failures to surface; fail-open
|
||||
contract: non-nil error allows the request
|
||||
|
||||
Reference in New Issue
Block a user