feat(06-03): add path-scoped CORS and per-route body limits
- CORS matches Laravel path globs (api/* includes nested segments); unlisted paths get no headers - Non-raw routes wrap http.MaxBytesReader from http.body_limits.default_bytes; body.limit:N overrides innermost - Raw routes stay uncapped at this layer
This commit is contained in:
@@ -143,7 +143,13 @@ func TestRecoverReturnsOpaqueJSON500(t *testing.T) {
|
||||
|
||||
func TestCORSPreflightBypassesNamedAuth(t *testing.T) {
|
||||
called := false
|
||||
r := New([]string{"http://localhost:3000"})
|
||||
r := New(nil)
|
||||
r.corsCfg = CORSConfig{
|
||||
Paths: []string{"api/*"},
|
||||
AllowedOrigins: []string{"http://localhost:3000"},
|
||||
AllowedMethods: []string{"GET", "POST", "PUT", "PATCH", "DELETE", "OPTIONS"},
|
||||
AllowedHeaders: []string{"Authorization", "Content-Type", "Accept"},
|
||||
}
|
||||
if err := r.RegisterMiddleware("golem15.user", "jwt.auth", func(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, req *http.Request) {
|
||||
called = true
|
||||
|
||||
Reference in New Issue
Block a user