CORS AllowedMethods omits PUT, making three API routes unreachable cross-origin
Description
The CORS config does not allow PUT, but three API routes are PUT-only, so browser preflight blocks them.
internal/server/server.go:132:
AllowedMethods: []string{"GET", "POST", "PATCH", "DELETE", "OPTIONS"},
PUT-only routes:
internal/server/server.go:208—r.Put("/favorite", s.favoriteProject)internal/server/server.go:219—r.Put("/members/{username}", s.grantProjectMember)internal/server/server.go:222—r.Put("/blocks/{username}", s.blockProjectUser)
Steps to reproduce
Send OPTIONS /api/v1/{owner}/projects/{key}/favorite with a configured allowed Origin and Access-Control-Request-Method: PUT.
Actual
200 with no Access-Control-Allow-* headers — go-chi/cors aborts the preflight when the requested method is not allowed. The browser then blocks the real request, so favorite, grant-member, and block-user are unreachable from any cross-origin browser client.
Expected
Preflight approved with Access-Control-Allow-Methods including PUT.
Fix
Add "PUT" (and "HEAD") to AllowedMethods. Add a preflight test per method so a future PUT route cannot regress this.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.