feat(web): move CORSOrigins to server.Config; web.New warns on empty CORS; align to v1.2.0
This commit is contained in:
@@ -6,6 +6,23 @@ This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html
|
||||
|
||||
---
|
||||
|
||||
## [1.2.0] — 2026-08-08
|
||||
|
||||
Minor — CORS configuration moved to its rightful struct; `web.New` made safe-by-default.
|
||||
|
||||
### Changed
|
||||
|
||||
- **`CORSOrigins` now lives on `server.Config`** (env var `EINHERJAR_SERVER_CORS_ORIGINS`), the
|
||||
struct its name advertises — it previously loaded into `web.Config`. `web.Config.AllowedOrigins`
|
||||
remains as a code-only override (no env tag). Wiring via `web.New` or the env var is unaffected.
|
||||
- Bumped `contracts`, `core` to v1.2.0.
|
||||
|
||||
### Added
|
||||
|
||||
- `web.New` logs a warning when no CORS origins are configured, instead of silently disabling CORS.
|
||||
- Package docs (`web`, `web/server`) document when to use `web.New` vs `server.New`, with compiling
|
||||
examples and the env-gated allow-all CORS convention.
|
||||
|
||||
## [1.1.3] — 2026-08-08
|
||||
|
||||
Patch — CORS documentation discoverability.
|
||||
|
||||
Reference in New Issue
Block a user