fix(14-05): surf answers OPTIONS on CORS paths with Laravel's HandleCors headers

- every OPTIONS on a CORS path: 204 with Cache-Control no-cache, private
- a preflight echoes the requested method (upper-cased) and headers when * allows any, with Vary and PHP's default Content-Type, as recorded from PHP
- README and the routing docs describe the answer
This commit is contained in:
Jakub Zych
2026-10-04 00:00:01 +02:00
parent 7eb0174612
commit b5d20b3bfd
4 changed files with 106 additions and 2 deletions

View File

@@ -221,3 +221,5 @@ cors:
```
This fragment belongs in `config/http.yaml`. List the frontend's exact origin; `*` is for public, credential-free APIs only.
surf answers every `OPTIONS` request on a CORS path itself, with 204, before any route runs, so a plugin never registers an `OPTIONS` route. A preflight gets the same headers Laravel's `HandleCors` sends: with `allowed_methods: ["*"]` the `Access-Control-Allow-Methods` value is the requested method, upper-cased, and with `allowed_headers: ["*"]` the `Access-Control-Allow-Headers` value is the requested header list.