diff options
author | Tamal Saha <tamal@appscode.com> | 2019-08-26 04:33:06 -0700 |
---|---|---|
committer | Antoine GIRARD <sapk@users.noreply.github.com> | 2019-08-26 13:33:06 +0200 |
commit | 6b3f52fe5f7db5b3122cc8481ab8fed83e273fde (patch) | |
tree | 9f5701c987e8d9972754ddfbeae287dfcb13e9c4 /routers | |
parent | 5409dec8fd29dfb7fcd7c0afb8a2d9682abc48b1 (diff) | |
download | gitea-6b3f52fe5f7db5b3122cc8481ab8fed83e273fde.tar.gz gitea-6b3f52fe5f7db5b3122cc8481ab8fed83e273fde.zip |
Run CORS handler first for /api routes (#7967)
Signed-off-by: Tamal Saha <tamal@appscode.com>
Diffstat (limited to 'routers')
-rw-r--r-- | routers/api/v1/api.go | 9 | ||||
-rw-r--r-- | routers/routes/routes.go | 8 |
2 files changed, 8 insertions, 9 deletions
diff --git a/routers/api/v1/api.go b/routers/api/v1/api.go index 69dfc89378..64c4b47a64 100644 --- a/routers/api/v1/api.go +++ b/routers/api/v1/api.go @@ -75,7 +75,6 @@ import ( "code.gitea.io/gitea/routers/api/v1/user" "gitea.com/macaron/binding" - "gitea.com/macaron/cors" "gitea.com/macaron/macaron" ) @@ -502,12 +501,6 @@ func RegisterRoutes(m *macaron.Macaron) { m.Get("/swagger", misc.Swagger) //Render V1 by default } - var handlers []macaron.Handler - if setting.EnableCORS { - handlers = append(handlers, cors.CORS(setting.CORSConfig)) - } - handlers = append(handlers, securityHeaders(), context.APIContexter(), sudo()) - m.Group("/v1", func() { // Miscellaneous if setting.API.EnableSwagger { @@ -853,7 +846,7 @@ func RegisterRoutes(m *macaron.Macaron) { m.Group("/topics", func() { m.Get("/search", repo.TopicSearch) }) - }, handlers...) + }, securityHeaders(), context.APIContexter(), sudo()) } func securityHeaders() macaron.Handler { diff --git a/routers/routes/routes.go b/routers/routes/routes.go index 5774c65eca..8c329a5f6f 100644 --- a/routers/routes/routes.go +++ b/routers/routes/routes.go @@ -41,6 +41,7 @@ import ( "gitea.com/macaron/binding" "gitea.com/macaron/cache" "gitea.com/macaron/captcha" + "gitea.com/macaron/cors" "gitea.com/macaron/csrf" "gitea.com/macaron/i18n" "gitea.com/macaron/macaron" @@ -951,9 +952,14 @@ func RegisterRoutes(m *macaron.Macaron) { m.Get("/swagger.v1.json", templates.JSONRenderer(), routers.SwaggerV1Json) } + var handlers []macaron.Handler + if setting.EnableCORS { + handlers = append(handlers, cors.CORS(setting.CORSConfig)) + } + handlers = append(handlers, ignSignIn) m.Group("/api", func() { apiv1.RegisterRoutes(m) - }, ignSignIn) + }, handlers...) m.Group("/api/internal", func() { // package name internal is ideal but Golang is not allowed, so we use private as package name. |