trackslash
TRACK-51 P2

CORS AllowedMethods omits PUT, making three API routes unreachable cross-origin

0
All issues

Description

The CORS config does not allow PUT, but three API routes are PUT-only, so browser preflight blocks them.

internal/server/server.go:132:

AllowedMethods: []string{"GET", "POST", "PATCH", "DELETE", "OPTIONS"},

PUT-only routes:

  • internal/server/server.go:208 — r.Put("/favorite", s.favoriteProject)
  • internal/server/server.go:219 — r.Put("/members/{username}", s.grantProjectMember)
  • internal/server/server.go:222 — r.Put("/blocks/{username}", s.blockProjectUser)

Steps to reproduce

Send OPTIONS /api/v1/{owner}/projects/{key}/favorite with a configured allowed Origin and Access-Control-Request-Method: PUT.

Actual

200 with no Access-Control-Allow-* headers — go-chi/cors aborts the preflight when the requested method is not allowed. The browser then blocks the real request, so favorite, grant-member, and block-user are unreachable from any cross-origin browser client.

Expected

Preflight approved with Access-Control-Allow-Methods including PUT.

Fix

Add "PUT" (and "HEAD") to AllowedMethods. Add a preflight test per method so a future PUT route cannot regress this.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.