A11 (C++ runtime)
Native C++ implementation of the A11 streaming action runtime
Loading...
Searching...
No Matches
server_headers.h
Go to the documentation of this file.
1/*
2 * Copyright 2026 The A11 Authors
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
35#ifndef A11_NET_SERVER_HEADERS_H_
36#define A11_NET_SERVER_HEADERS_H_
37
38#include <string>
39#include <string_view>
40
41#include <absl/status/status.h>
42
43#include "a11/net/http2.h"
44
45namespace a11::net {
46
48inline constexpr std::string_view kServerHeaderValue = "a11";
49
64 bool enabled = true;
66 std::string allow_origin = "*";
68 std::string allow_methods = "GET, POST, OPTIONS";
71 std::string allow_headers = "content-type, accept, authorization, x-a11-*";
81 std::string expose_headers = "x-a11-stream-id, x-a11-outbound";
84 int max_age_seconds = 600;
85
87 [[nodiscard]] absl::Status Validate() const;
88};
89
98enum class CachePolicy {
100 kStream,
102 kVolatile,
104 kUnset,
105};
106
114 std::string server = std::string(kServerHeaderValue);
118 bool nosniff = true;
119
121 [[nodiscard]] absl::Status Validate() const;
122};
123
134void ApplyServerHeaders(const ServerHeaderOptions& options, CachePolicy cache,
135 HttpHeaders* absl_nonnull headers);
136
143[[nodiscard]] HttpHeaders CorsHeaders(const CorsOptions& options);
144
152void ApplyCorsHeaders(const CorsOptions& options,
153 HttpHeaders* absl_nonnull headers);
154
158[[nodiscard]] bool IsPreflight(const CorsOptions& options,
159 std::string_view method);
160
161} // namespace a11::net
162
163#endif // A11_NET_SERVER_HEADERS_H_
A11's nghttp2 HTTP/2 client, server, and streaming primitives.
Definition action.h:65
std::vector< std::pair< std::string, std::string > > HttpHeaders
An ordered list of (name, value) HTTP/2 header fields.
Definition http2.h:70
HttpHeaders CorsHeaders(const CorsOptions &options)
The cross-origin headers for options, and nothing else.
Definition server_headers.cc:129
constexpr std::string_view kServerHeaderValue
Value of the Server header A11's HTTP surfaces send.
Definition server_headers.h:48
void ApplyCorsHeaders(const CorsOptions &options, HttpHeaders *absl_nonnull headers)
Adds the cross-origin headers for options to headers.
Definition server_headers.cc:99
@ kStream
One long-lived request body carrying every outbound message.
bool IsPreflight(const CorsOptions &options, std::string_view method)
Whether method is a CORS preflight this policy should answer.
Definition server_headers.cc:163
CachePolicy
How a response may be cached, which differs by what it is.
Definition server_headers.h:98
@ kVolatile
A document that may change at any time. no-cache: use it, but ask first.
@ kUnset
Say nothing, and leave caching to whatever default applies.
void ApplyServerHeaders(const ServerHeaderOptions &options, CachePolicy cache, HttpHeaders *absl_nonnull headers)
Adds the headers every response from an A11 server carries.
Definition server_headers.cc:135
Cross-origin policy for an A11 HTTP surface.
Definition server_headers.h:62
int max_age_seconds
Access-Control-Max-Age in seconds; 0 omits it.
Definition server_headers.h:84
std::string allow_origin
Access-Control-Allow-Origin. * admits any page.
Definition server_headers.h:66
absl::Status Validate() const
Definition server_headers.cc:71
std::string allow_headers
Access-Control-Allow-Headers.
Definition server_headers.h:71
bool enabled
Whether cross-origin headers are sent at all.
Definition server_headers.h:64
std::string expose_headers
Access-Control-Expose-Headers: what a page may read off the response.
Definition server_headers.h:81
std::string allow_methods
Access-Control-Allow-Methods. Every method A11's routes use.
Definition server_headers.h:68
The response-header policy of one A11 HTTP surface.
Definition server_headers.h:112
absl::Status Validate() const
Definition server_headers.cc:91
bool nosniff
Send X-Content-Type-Options: nosniff.
Definition server_headers.h:118
CorsOptions cors
Definition server_headers.h:115
std::string server
Server value; empty sends none.
Definition server_headers.h:114