handlers.go 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150
  1. package cors
  2. import (
  3. "bufio"
  4. "errors"
  5. "net"
  6. "net/http"
  7. )
  8. const (
  9. allowOrigin = "Access-Control-Allow-Origin"
  10. allOrigins = "*"
  11. allowMethods = "Access-Control-Allow-Methods"
  12. allowHeaders = "Access-Control-Allow-Headers"
  13. allowCredentials = "Access-Control-Allow-Credentials"
  14. exposeHeaders = "Access-Control-Expose-Headers"
  15. requestMethod = "Access-Control-Request-Method"
  16. requestHeaders = "Access-Control-Request-Headers"
  17. allowHeadersVal = "Content-Type, Origin, X-CSRF-Token, Authorization, AccessToken, Token, Range"
  18. exposeHeadersVal = "Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers"
  19. methods = "GET, HEAD, POST, PATCH, PUT, DELETE"
  20. allowTrue = "true"
  21. maxAgeHeader = "Access-Control-Max-Age"
  22. maxAgeHeaderVal = "86400"
  23. varyHeader = "Vary"
  24. originHeader = "Origin"
  25. )
  26. // NotAllowedHandler handles cross domain not allowed requests.
  27. // At most one origin can be specified, other origins are ignored if given, default to be *.
  28. func NotAllowedHandler(fn func(w http.ResponseWriter), origins ...string) http.Handler {
  29. return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  30. gw := &guardedResponseWriter{w: w}
  31. checkAndSetHeaders(gw, r, origins)
  32. if fn != nil {
  33. fn(gw)
  34. }
  35. if r.Method == http.MethodOptions {
  36. gw.WriteHeader(http.StatusNoContent)
  37. } else {
  38. gw.WriteHeader(http.StatusNotFound)
  39. }
  40. })
  41. }
  42. // Middleware returns a middleware that adds CORS headers to the response.
  43. func Middleware(fn func(w http.Header), origins ...string) func(http.HandlerFunc) http.HandlerFunc {
  44. return func(next http.HandlerFunc) http.HandlerFunc {
  45. return func(w http.ResponseWriter, r *http.Request) {
  46. checkAndSetHeaders(w, r, origins)
  47. if fn != nil {
  48. fn(w.Header())
  49. }
  50. if r.Method == http.MethodOptions {
  51. w.WriteHeader(http.StatusNoContent)
  52. } else {
  53. next(w, r)
  54. }
  55. }
  56. }
  57. }
  58. type guardedResponseWriter struct {
  59. w http.ResponseWriter
  60. wroteHeader bool
  61. }
  62. func (w *guardedResponseWriter) Flush() {
  63. if flusher, ok := w.w.(http.Flusher); ok {
  64. flusher.Flush()
  65. }
  66. }
  67. func (w *guardedResponseWriter) Header() http.Header {
  68. return w.w.Header()
  69. }
  70. // Hijack implements the http.Hijacker interface.
  71. // This expands the Response to fulfill http.Hijacker if the underlying http.ResponseWriter supports it.
  72. func (w *guardedResponseWriter) Hijack() (net.Conn, *bufio.ReadWriter, error) {
  73. if hijacked, ok := w.w.(http.Hijacker); ok {
  74. return hijacked.Hijack()
  75. }
  76. return nil, nil, errors.New("server doesn't support hijacking")
  77. }
  78. func (w *guardedResponseWriter) Write(bytes []byte) (int, error) {
  79. return w.w.Write(bytes)
  80. }
  81. func (w *guardedResponseWriter) WriteHeader(code int) {
  82. if w.wroteHeader {
  83. return
  84. }
  85. w.w.WriteHeader(code)
  86. w.wroteHeader = true
  87. }
  88. func checkAndSetHeaders(w http.ResponseWriter, r *http.Request, origins []string) {
  89. setVaryHeaders(w, r)
  90. if len(origins) == 0 {
  91. setHeader(w, allOrigins)
  92. return
  93. }
  94. origin := r.Header.Get(originHeader)
  95. if isOriginAllowed(origins, origin) {
  96. setHeader(w, origin)
  97. }
  98. }
  99. func isOriginAllowed(allows []string, origin string) bool {
  100. for _, o := range allows {
  101. if o == allOrigins {
  102. return true
  103. }
  104. if o == origin {
  105. return true
  106. }
  107. }
  108. return false
  109. }
  110. func setHeader(w http.ResponseWriter, origin string) {
  111. header := w.Header()
  112. header.Set(allowOrigin, origin)
  113. header.Set(allowMethods, methods)
  114. header.Set(allowHeaders, allowHeadersVal)
  115. header.Set(exposeHeaders, exposeHeadersVal)
  116. if origin != allOrigins {
  117. header.Set(allowCredentials, allowTrue)
  118. }
  119. header.Set(maxAgeHeader, maxAgeHeaderVal)
  120. }
  121. func setVaryHeaders(w http.ResponseWriter, r *http.Request) {
  122. header := w.Header()
  123. header.Add(varyHeader, originHeader)
  124. if r.Method == http.MethodOptions {
  125. header.Add(varyHeader, requestMethod)
  126. header.Add(varyHeader, requestHeaders)
  127. }
  128. }