5 Commits

Author SHA1 Message Date
codeskyblue
b86e0e623e cors enable by default 2023-12-19 11:05:52 +08:00
codeskyblue
bca7b842f5 Merge pull request #191 from codeskyblue/limit-cors
limit cors only get, head, options
2023-12-19 10:38:43 +08:00
codeskyblue
ea7272437d limit cors only get, head, options 2023-12-19 10:37:39 +08:00
codeskyblue
80c9e79869 update again 2022-07-26 19:23:30 +08:00
codeskyblue
2adc57be6c change ci from travis to github actions 2022-07-26 18:44:49 +08:00
5 changed files with 51 additions and 30 deletions

34
.github/workflows/release.yml vendored Normal file
View File

@@ -0,0 +1,34 @@
name: goreleaser
on:
push:
# run only against tags
tags:
- '*'
permissions:
contents: write
# packages: write
# issues: write
jobs:
goreleaser:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v2
with:
fetch-depth: 0
- name: Fetch all tags
run: git fetch --force --tags
- name: Set up Go
uses: actions/setup-go@v2
with:
go-version: 1.18
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v2
with:
# either 'goreleaser' (default) or 'goreleaser-pro'
distribution: goreleaser
version: latest
args: release --rm-dist
env:
GITHUB_TOKEN: ${{ secrets.TOKEN }}

1
.gitignore vendored
View File

@@ -31,3 +31,4 @@ assets_vfsdata.go
*.swp
dist/
.DS_Store

View File

@@ -1,25 +0,0 @@
services:
- docker
language: go
go:
- "1.18"
env:
- GO111MODULE=on
script:
- go test -v
addons:
apt:
packages:
- docker-ce
deploy:
- provider: script
skip_cleanup: true
script: curl -sL https://git.io/goreleaser | bash
on:
tags: true
condition: $TRAVIS_OS_NAME = linux
#- provider: script
# skip_cleanup: true
# script: bash docker/push_images && bash docker/push_manifest
# on:
# branch: master

20
main.go
View File

@@ -33,7 +33,6 @@ type Configure struct {
HTTPAuth string `yaml:"httpauth"`
Cert string `yaml:"cert"`
Key string `yaml:"key"`
Cors bool `yaml:"cors"`
Theme string `yaml:"theme"`
XHeaders bool `yaml:"xheaders"`
Upload bool `yaml:"upload"`
@@ -116,7 +115,6 @@ func parseFlags() error {
kingpin.Flag("upload", "enable upload support").BoolVar(&gcfg.Upload)
kingpin.Flag("delete", "enable delete support").BoolVar(&gcfg.Delete)
kingpin.Flag("xheaders", "used when behide nginx").BoolVar(&gcfg.XHeaders)
kingpin.Flag("cors", "enable cross-site HTTP request").BoolVar(&gcfg.Cors)
kingpin.Flag("debug", "enable debug mode").BoolVar(&gcfg.Debug)
kingpin.Flag("plistproxy", "plist proxy when server is not https").Short('p').StringVar(&gcfg.PlistProxy)
kingpin.Flag("title", "server title").StringVar(&gcfg.Title)
@@ -148,6 +146,19 @@ func fixPrefix(prefix string) string {
return prefix
}
func cors(next http.Handler) http.Handler {
// access control and CORS middleware
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Access-Control-Allow-Origin", "*")
w.Header().Set("Access-Control-Allow-Methods", "*")
w.Header().Set("Access-Control-Allow-Headers", "*")
if r.Method == "OPTIONS" {
return
}
next.ServeHTTP(w, r)
})
}
func main() {
if err := parseFlags(); err != nil {
log.Fatal(err)
@@ -206,9 +217,8 @@ func main() {
}
// CORS
if gcfg.Cors {
hdlr = handlers.CORS()(hdlr)
}
hdlr = cors(hdlr)
if gcfg.XHeaders {
hdlr = handlers.ProxyHeaders(hdlr)
}

1
testdata/filetypes/script.js vendored Normal file
View File

@@ -0,0 +1 @@
document.write("Hello world!")