clarified cors wildcard support

This commit is contained in:
Gani Georgiev committed 2026-09-26 08:03:15 +03:00
1 parent 2ae117228e
commit 211b9645ee
1 file changed
+5 -3
+5 -3
View File
@@ -31,9 +31,11 @@ const (
// CORSConfig defines the config for CORS middleware.
type CORSConfig struct {
// AllowOrigins determines the value of the Access-Control-Allow-Origin
// response header. This header defines a list of origins that may access the
// resource. The wildcard characters '*' and '?' are supported and are
// converted to regex fragments '.*' and '.' accordingly.
// response header. This header defines a list of origins that may access the
// resource.
//
// The wildcard characters '*' and '?' are supported as subdomain segments
// and are converted to regex fragments '.*' and '.' accordingly.
//
// Security: use extreme caution when handling the origin, and carefully
// validate any logic. Remember that attackers may register hostile domain names.