Repository navigation
feat(server): add CORS preflight support - #238
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fix F06: browser preflights for registered endpoints currently receive 405 before application middleware can handle them. Add opt-in
ServerBuilder.useCors(options)and the exportedServerCorsOptionstype. Accepted preflights now receive an empty 204 before authentication or ordinary middleware; actual protected requests keep their existing authentication pipeline.Support exact origin lists, explicit public wildcard origins, and synchronous/asynchronous origin predicates. Disallowed origins return 403 before handlers run; callback failures return a generic 500. Method/header preflight allowlists, exposed response headers, credentials and browser cache duration are configurable. Configuration is validated and copied before listening, and wildcard origins cannot be combined with credentials.
Preflight matching includes typed routes, health checks and the configured batch endpoint. Finalize CORS headers per physical response, preserve existing Vary values, and prevent cache/idempotency replays from reusing another origin's permissions. Cover successful and error responses, implicit/native header writes, cookies, and streamed results. Virtual batch requests retain their existing auth pipeline; CORS applies to the outer HTTP request.
CORS is disabled by default. Requests without Origin and ordinary OPTIONS requests retain their normal pipeline. Method/header lists govern preflight permission, not ordinary HTTP routing. WebSocket origin policy and consumer application changes are outside this PR.
Includes a minor server changeset, updated server documentation/examples, and the F06 implementation status.
Type of Change
Validation
npm run lint— passednpm run build— all 24 tasks passednpm run test— 4,545 tests across 232 files passed; no type errorsnpm run typecheck:schema-site— passednpm run typecheck:docs-site— passedgit diff --check— passedThe suite adds 60 CORS unit, type and real HTTP cases. Coverage includes preflight/auth separation, origin rejection before handlers, callback reevaluation/failure, malformed input, method/header restrictions, credentials, error responses, built-in routes, native header overloads, Vary merging and cache/idempotency replay across origins.
Existing behavior observed during testing: the JSON body-size limit path in
RequestContext.body()destroys the request socket before its intended 413 response reaches the client. That transport behavior is unchanged; CORS headers apply to HTTP responses that are emitted.Checklist
npm run lintand fixed any issuesnpm run testand all tests pass