A11 (C++ runtime)
Native C++ implementation of the A11 streaming action runtime
Loading...
Searching...
No Matches
a11::net::CorsOptions Struct Reference

Cross-origin policy for an A11 HTTP surface. More...

#include <cpp/a11/net/server_headers.h>

Public Member Functions

absl::Status Validate () const
 

Public Attributes

bool enabled = true
 Whether cross-origin headers are sent at all.
 
std::string allow_origin = "*"
 Access-Control-Allow-Origin. * admits any page.
 
std::string allow_methods = "GET, POST, OPTIONS"
 Access-Control-Allow-Methods. Every method A11's routes use.
 
std::string allow_headers = "content-type, accept, authorization, x-a11-*"
 Access-Control-Allow-Headers.
 
std::string expose_headers = "x-a11-stream-id, x-a11-outbound"
 Access-Control-Expose-Headers: what a page may read off the response.
 
int max_age_seconds = 600
 Access-Control-Max-Age in seconds; 0 omits it.
 

Detailed Description

Cross-origin policy for an A11 HTTP surface.

Permissive by default. A11's browser clients are a primary use case because pages cannot open raw sockets. Configure allow_origin for a narrower policy, or clear enabled to disable cross-origin access.

This is not a security boundary and must not be read as one. CORS governs what a browser will let a page read; it says nothing to anything else. An A11 server that should not be reachable is one that is not listening publicly.

Member Function Documentation

◆ Validate()

absl::Status a11::net::CorsOptions::Validate ( ) const
Returns
OK if no value would inject a header break.

Member Data Documentation

◆ allow_headers

std::string a11::net::CorsOptions::allow_headers = "content-type, accept, authorization, x-a11-*"

Access-Control-Allow-Headers.

A11's own header prefix plus the ones a JSON or SSE request carries.

◆ allow_methods

std::string a11::net::CorsOptions::allow_methods = "GET, POST, OPTIONS"

Access-Control-Allow-Methods. Every method A11's routes use.

◆ allow_origin

std::string a11::net::CorsOptions::allow_origin = "*"

Access-Control-Allow-Origin. * admits any page.

◆ enabled

bool a11::net::CorsOptions::enabled = true

Whether cross-origin headers are sent at all.

◆ expose_headers

std::string a11::net::CorsOptions::expose_headers = "x-a11-stream-id, x-a11-outbound"

Access-Control-Expose-Headers: what a page may read off the response.

A11's own response headers, by default, because the SSE transport does not work without them: a browser client reads its stream id and the outbound modes the server offers off the connect response, and a header a page may not read is one it did not receive. This defaulting to empty is why every page-facing deployment had to discover and set it.

◆ max_age_seconds

int a11::net::CorsOptions::max_age_seconds = 600

Access-Control-Max-Age in seconds; 0 omits it.

A preflight per request is a round trip per request, and these routes' policy does not change.


The documentation for this struct was generated from the following files: