From 211b9645ee8009a824eacff66c52ef6d77e2d5ce Mon Sep 17 00:00:00 2001 From: Gani Georgiev Date: Sat, 26 Sep 2026 08:03:15 +0300 Subject: [PATCH] clarified cors wildcard support --- apis/middlewares_cors.go | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/apis/middlewares_cors.go b/apis/middlewares_cors.go index 204586d0..4108b27a 100644 --- a/apis/middlewares_cors.go +++ b/apis/middlewares_cors.go @@ -31,9 +31,11 @@ const ( // CORSConfig defines the config for CORS middleware. type CORSConfig struct { // AllowOrigins determines the value of the Access-Control-Allow-Origin - // response header. This header defines a list of origins that may access the - // resource. The wildcard characters '*' and '?' are supported and are - // converted to regex fragments '.*' and '.' accordingly. + // response header. This header defines a list of origins that may access the + // resource. + // + // The wildcard characters '*' and '?' are supported as subdomain segments + // and are converted to regex fragments '.*' and '.' accordingly. // // Security: use extreme caution when handling the origin, and carefully // validate any logic. Remember that attackers may register hostile domain names.