pub struct Config {
pub origins: Vec<String>,
pub origin_matchers: Vec<OriginMatcher>,
pub methods: Vec<Method>,
pub headers: Vec<HeaderName>,
pub allow_credentials: bool,
pub max_age_secs: Option<u32>,
pub allow_private_network: bool,
}plugins only.Expand description
CORS policy configuration settings for cross-origin request handling.
Config defines the Cross-Origin Resource Sharing policy including allowed origins,
HTTP methods, headers, credential handling, and preflight cache duration. The
configuration determines which cross-origin requests are permitted and what headers
are added to responses to enable secure cross-origin communication.
§Examples
use tako::plugins::cors::Config;
use http::{Method, HeaderName};
let config = Config {
origins: vec!["https://app.example.com".to_string()],
methods: vec![Method::GET, Method::POST],
headers: vec![HeaderName::from_static("x-api-key")],
allow_credentials: true,
max_age_secs: Some(3600),
};Fields§
§origins: Vec<String>Exact origin allow-list (legacy). For wider matching, use Self::origin_matchers.
origin_matchers: Vec<OriginMatcher>Suffix / regex / custom origin matchers (additive on top of origins).
methods: Vec<Method>List of allowed HTTP methods for cross-origin requests.
headers: Vec<HeaderName>List of allowed request headers for cross-origin requests.
allow_credentials: boolWhether to allow credentials (cookies, authorization headers) in cross-origin requests.
max_age_secs: Option<u32>Maximum age in seconds for preflight request caching by browsers.
allow_private_network: boolSend Access-Control-Allow-Private-Network: true in preflight responses
when the client signals Access-Control-Request-Private-Network: true.
Required for browsers to allow public→private requests post Chrome 104.
Implementations§
Source§impl Config
impl Config
Sourcepub fn validate(&self) -> Result<(), CorsConfigError>
pub fn validate(&self) -> Result<(), CorsConfigError>
Validates the CORS configuration against the Fetch spec’s hard rules.
Returns an error if the configuration would produce a header combination that
browsers reject (e.g. Access-Control-Allow-Origin: * together with
Access-Control-Allow-Credentials: true).
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for Config
impl !UnwindSafe for Config
impl Freeze for Config
impl Send for Config
impl Sync for Config
impl Unpin for Config
impl UnsafeUnpin for Config
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self>
fn with_context(self, otel_cx: Context) -> WithContext<Self>
Source§fn with_current_context(self) -> WithContext<Self>
fn with_current_context(self) -> WithContext<Self>
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more