HH-547: allow cross-origin widget requests (#126)

* HH-547: allow cross-origin widget requests

* fix(HH-547): align production preflight with wildcard CORS

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-23 20:11:04 +08:00
committed by GitHub
co-authored by rogee
parent a2e4f9a1e8
commit eb83d241fe
13 changed files with 79 additions and 50 deletions
@@ -22,7 +22,7 @@ func validReleaseConfig() *Config {
}
}
func TestReleaseTransportAndCORSValidationFailsClosed(t *testing.T) {
func TestReleaseTransportValidationFailsClosed(t *testing.T) {
tests := []struct {
name string
mutate func(*Config)
@@ -30,9 +30,6 @@ func TestReleaseTransportAndCORSValidationFailsClosed(t *testing.T) {
}{
{"database TLS without identity verification", func(c *Config) { c.Database.DSN = "postgres://user:pass@db.acme.test/gochat?sslmode=require" }, "sslmode=disable, verify-full or verify-ca"},
{"redis certificate not verified", func(c *Config) { c.Redis.DSN = "rediss://:redis-secret@redis.acme.test:6379?insecure_skip_verify=true" }, "cannot be disabled"},
{"placeholder origin", func(c *Config) { c.Server.CORS.AllowedOrigins = []string{"https://example.com"} }, "not deployable"},
{"non HTTPS origin", func(c *Config) { c.Server.CORS.AllowedOrigins = []string{"http://chat.acme.test"} }, "exact HTTPS origin"},
{"wildcard origin", func(c *Config) { c.Server.CORS.AllowedOrigins = []string{"*.acme.test"} }, "exact HTTPS origin"},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
-13
View File
@@ -136,19 +136,6 @@ func Validate(cfg *Config) error {
if redisURL.Scheme == "rediss" && strings.EqualFold(redisURL.Query().Get("insecure_skip_verify"), "true") {
return fmt.Errorf("production Redis TLS certificate verification cannot be disabled")
}
if len(cfg.Server.CORS.AllowedOrigins) == 0 {
return fmt.Errorf("production CORS requires at least one HTTPS origin")
}
for _, origin := range cfg.Server.CORS.AllowedOrigins {
parsed, err := url.Parse(origin)
lower := strings.ToLower(origin)
if err != nil || parsed.Scheme != "https" || parsed.Host == "" || parsed.Path != "" || parsed.RawQuery != "" || parsed.Fragment != "" {
return fmt.Errorf("production CORS origin must be an exact HTTPS origin: %q", origin)
}
if strings.Contains(origin, "*") || strings.Contains(lower, "localhost") || strings.Contains(lower, "example.") || strings.Contains(lower, "yourdomain") || containsPlaceholder(origin) {
return fmt.Errorf("production CORS origin is not deployable: %q", origin)
}
}
if cfg.JWT.AccessExpiryMinutes <= 0 || cfg.JWT.AccessExpiryMinutes > 15 {
return fmt.Errorf("production JWT access_expiry_minutes must be between 1 and 15")
}