feat(web): move CORSOrigins to server.Config; web.New warns on empty CORS; align to v1.2.0

This commit is contained in:
2026-08-08 02:24:08 -06:00
parent fc3fe750d4
commit c611e67946
8 changed files with 94 additions and 24 deletions
+17
View File
@@ -6,6 +6,23 @@ This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html
---
## [1.2.0] — 2026-08-08
Minor — CORS configuration moved to its rightful struct; `web.New` made safe-by-default.
### Changed
- **`CORSOrigins` now lives on `server.Config`** (env var `EINHERJAR_SERVER_CORS_ORIGINS`), the
struct its name advertises — it previously loaded into `web.Config`. `web.Config.AllowedOrigins`
remains as a code-only override (no env tag). Wiring via `web.New` or the env var is unaffected.
- Bumped `contracts`, `core` to v1.2.0.
### Added
- `web.New` logs a warning when no CORS origins are configured, instead of silently disabling CORS.
- Package docs (`web`, `web/server`) document when to use `web.New` vs `server.New`, with compiling
examples and the env-gated allow-all CORS convention.
## [1.1.3] — 2026-08-08
Patch — CORS documentation discoverability.