fix(web): mw.CORS rejects wildcard; fix README fences; align to v1.1.2

This commit is contained in:
2026-08-08 00:43:09 -06:00
parent c6a753e49b
commit 8876af3bfa
5 changed files with 38 additions and 13 deletions
+17 -1
View File
@@ -6,6 +6,22 @@ This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html
---
## [1.1.2] — 2026-08-08
Patch — CORS wildcard hardening plus documentation fixes.
### Changed
- **`mw.CORS` now rejects `"*"` (panics at construction)** instead of silently no-op'ing it.
`"*"` matched nothing (exact-match only), so a service passing it ran with CORS effectively
off — a silent trap. Fail loud at boot; use `mw.CORSAllowAll()` (development) or list explicit origins.
- Bumped `contracts`, `core` to v1.1.2.
### Fixed
- README Go examples now compile: `mw.Recover(logger)`, `health.NewHandler(...).ServeHTTP`, and the
`mw.CORS` example no longer passes `"*"`. Corrected the `CORSAllowAll` description.
## [1.1.1] — 2026-08-07
Patch — coordinated framework version alignment.
@@ -69,7 +85,7 @@ Coordinated framework release. Documentation fixes plus the framework version bu
request logging: method, path, status, latency; uses `StatusRecorder` to capture code
- `CORS(origins []string) func(http.Handler) http.Handler` — sets
`Access-Control-Allow-Origin` for listed origins; supports preflight (`OPTIONS`)
- `CORSAllowAll() func(http.Handler) http.Handler`shorthand for `CORS([]string{"*"})`
- `CORSAllowAll() func(http.Handler) http.Handler`allows any origin by reflecting the request `Origin` (no `Access-Control-Allow-Credentials`); development only
- `RateLimiterStore` interface — `Allow(ctx context.Context, key string) (bool, error)`;
pluggable backend; `error` return allows infrastructure failures to surface; fail-open
contract: non-nil error allows the request