pub struct CorsPlugin {
allowed_origins: Vec<String>,
allowed_methods: Vec<Template>,
allowed_headers: Vec<Template>,
max_age: u64,
allow_credentials: bool,
}Expand description
Applies CORS response headers based on the request’s Origin header.
For an allowed origin the plugin sets access-control-allow-origin
(echoing the origin, or * when wildcarded) and, when enabled,
access-control-allow-credentials. For preflight (OPTIONS) requests it
additionally sets the allow-methods/allow-headers/max-age headers,
prepares a 204 empty response, and exits through the preflight port —
the policy must wire that port (typically straight to client) or
compilation rejects it. Does not write to context.message and always
succeeds.
Fields§
§allowed_origins: Vec<String>Origins granted CORS access; "*" matches any origin. Never
templated — semantic tokens (*/origin-echo) stay literal.
allowed_methods: Vec<Template>Methods advertised in preflight responses. Values support
{{namespace.path}} references (no legacy $var interpolation —
these headers never supported it, so this sweep must not start).
allowed_headers: Vec<Template>Request headers advertised in preflight responses; may be "*".
Values support {{namespace.path}} references, same as
allowed_methods.
max_age: u64Preflight cache lifetime in seconds (access-control-max-age).
allow_credentials: boolWhether to emit access-control-allow-credentials: true.
Implementations§
Source§impl CorsPlugin
impl CorsPlugin
Sourcepub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
pub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
Builds the plugin from node config. Never fails; every key has a default.
Accepted keys:
allowed_origins(array of strings, default["*"]) — never templated; semantic tokens (*/origin-echo) stay literal.allowed_methods(array of strings, default["GET", "POST", "PUT", "DELETE", "OPTIONS"]); values support{{namespace.path}}references.allowed_headers(array of strings, default["*"]); values support{{namespace.path}}references.max_age(integer seconds, default3600)allow_credentials(bool, defaultfalse)
type: cors
config:
allowed_origins: ["https://app.example.com"]
allowed_methods: ["GET", "POST"]
max_age: 600
allow_credentials: trueSourcefn origin_allowed(&self, origin: &str) -> bool
fn origin_allowed(&self, origin: &str) -> bool
Returns true when the origin exactly matches an allowed origin or the
list contains the "*" wildcard.
Trait Implementations§
Source§impl Plugin for CorsPlugin
impl Plugin for CorsPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Source§fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
Source§fn reads_response_body(&self) -> bool
fn reads_response_body(&self) -> bool
context.response.body. Read moreSource§fn cache_target(&self) -> Option<CacheTarget>
fn cache_target(&self) -> Option<CacheTarget>
proxy-cache half. Read moreAuto Trait Implementations§
impl Freeze for CorsPlugin
impl RefUnwindSafe for CorsPlugin
impl Send for CorsPlugin
impl Sync for CorsPlugin
impl Unpin for CorsPlugin
impl UnsafeUnpin for CorsPlugin
impl UnwindSafe for CorsPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more