|
A11 (C++ runtime)
Native C++ implementation of the A11 streaming action runtime
|
Cross-origin policy for an A11 HTTP surface. More...
#include <cpp/a11/net/server_headers.h>
Public Member Functions | |
| absl::Status | Validate () const |
Public Attributes | |
| bool | enabled = true |
| Whether cross-origin headers are sent at all. | |
| std::string | allow_origin = "*" |
Access-Control-Allow-Origin. * admits any page. | |
| std::string | allow_methods = "GET, POST, OPTIONS" |
Access-Control-Allow-Methods. Every method A11's routes use. | |
| std::string | allow_headers = "content-type, accept, authorization, x-a11-*" |
Access-Control-Allow-Headers. | |
| std::string | expose_headers = "x-a11-stream-id, x-a11-outbound" |
Access-Control-Expose-Headers: what a page may read off the response. | |
| int | max_age_seconds = 600 |
Access-Control-Max-Age in seconds; 0 omits it. | |
Cross-origin policy for an A11 HTTP surface.
Permissive by default. A11's browser clients are a primary use case because pages cannot open raw sockets. Configure allow_origin for a narrower policy, or clear enabled to disable cross-origin access.
This is not a security boundary and must not be read as one. CORS governs what a browser will let a page read; it says nothing to anything else. An A11 server that should not be reachable is one that is not listening publicly.
| absl::Status a11::net::CorsOptions::Validate | ( | ) | const |
| std::string a11::net::CorsOptions::allow_headers = "content-type, accept, authorization, x-a11-*" |
Access-Control-Allow-Headers.
A11's own header prefix plus the ones a JSON or SSE request carries.
| std::string a11::net::CorsOptions::allow_methods = "GET, POST, OPTIONS" |
Access-Control-Allow-Methods. Every method A11's routes use.
| std::string a11::net::CorsOptions::allow_origin = "*" |
Access-Control-Allow-Origin. * admits any page.
| bool a11::net::CorsOptions::enabled = true |
Whether cross-origin headers are sent at all.
| std::string a11::net::CorsOptions::expose_headers = "x-a11-stream-id, x-a11-outbound" |
Access-Control-Expose-Headers: what a page may read off the response.
A11's own response headers, by default, because the SSE transport does not work without them: a browser client reads its stream id and the outbound modes the server offers off the connect response, and a header a page may not read is one it did not receive. This defaulting to empty is why every page-facing deployment had to discover and set it.
| int a11::net::CorsOptions::max_age_seconds = 600 |
Access-Control-Max-Age in seconds; 0 omits it.
A preflight per request is a round trip per request, and these routes' policy does not change.