Skip to content

feat(server): add CORS preflight support - #238

Merged
andrewzolotukhin merged 1 commit into
developmentfrom
feat/cors-preflight
Oct 2, 2026
Merged

andrewzolotukhin merged 1 commit into
developmentfrom
feat/cors-preflight

Conversation

@andrewzolotukhin

Copy link
Copy Markdown
Contributor

Description

Fix F06: browser preflights for registered endpoints currently receive 405 before application middleware can handle them. Add opt-in ServerBuilder.useCors(options) and the exported ServerCorsOptions type. Accepted preflights now receive an empty 204 before authentication or ordinary middleware; actual protected requests keep their existing authentication pipeline.

Support exact origin lists, explicit public wildcard origins, and synchronous/asynchronous origin predicates. Disallowed origins return 403 before handlers run; callback failures return a generic 500. Method/header preflight allowlists, exposed response headers, credentials and browser cache duration are configurable. Configuration is validated and copied before listening, and wildcard origins cannot be combined with credentials.

Preflight matching includes typed routes, health checks and the configured batch endpoint. Finalize CORS headers per physical response, preserve existing Vary values, and prevent cache/idempotency replays from reusing another origin's permissions. Cover successful and error responses, implicit/native header writes, cookies, and streamed results. Virtual batch requests retain their existing auth pipeline; CORS applies to the outer HTTP request.

CORS is disabled by default. Requests without Origin and ordinary OPTIONS requests retain their normal pipeline. Method/header lists govern preflight permission, not ordinary HTTP routing. WebSocket origin policy and consumer application changes are outside this PR.

Includes a minor server changeset, updated server documentation/examples, and the F06 implementation status.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Refactor / internal improvement

Validation

  • npm run lint — passed
  • npm run build — all 24 tasks passed
  • npm run test — 4,545 tests across 232 files passed; no type errors
  • npm run typecheck:schema-site — passed
  • npm run typecheck:docs-site — passed
  • git diff --check — passed

The suite adds 60 CORS unit, type and real HTTP cases. Coverage includes preflight/auth separation, origin rejection before handlers, callback reevaluation/failure, malformed input, method/header restrictions, credentials, error responses, built-in routes, native header overloads, Vary merging and cache/idempotency replay across origins.

Existing behavior observed during testing: the JSON body-size limit path in RequestContext.body() destroys the request socket before its intended 413 response reaches the client. That transport behavior is unchanged; CORS headers apply to HTTP responses that are emitted.

Checklist

  • I've added tests for my changes
  • I've run npm run lint and fixed any issues
  • I've run npm run test and all tests pass
  • I've added a changeset if this changes package behavior

@andrewzolotukhin
andrewzolotukhin merged commit ef38a26 into development Oct 2, 2026
3 checks passed
@andrewzolotukhin
andrewzolotukhin deleted the feat/cors-preflight branch October 2, 2026 20:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant