Repository navigation
Do not duplicate headers #45
Description
Activity
Those headers are added using the
Header.Setmethod that is supposed to replace any existing occurrence of the header. Are you sure that the other thing adding this header does not happen aftercorshandler? Be aware that thecorshandler will add those headers before entering your handler, not after.So if CORS handler wraps another handler, it will set these before the other handler is even run?
The actual use case I'm working on is CORS handler wrapping reverse proxy. And sometimes the responses from upstream return CORS headers by themselves and I see duplicates.
Wouldn't it be better to add CORS headers after the wrapped handler finishes?
After the handler is gonna be too late: headers and body are already sent.
Reacted by jub0bsYou're right, that seems like a shortcoming of go's handler design. I guess there' not much this library can do.
Actually I stumbled upon this solution: https://stackoverflow.com/a/38335233/177591
Where they provide ResponseWriter implementation that let's them inject headers just before WriteHeader call.
Your thoughts @rs?
I know this solution but it's quite hacky. The example provided will hide the optional interfaces implemented by the
ResponseWriterlikeFlusher,HijackerorPusher. There are some tricks to expose them but I don't think it's worth it for this package.For your proxy issue, why don't you just cleanup the CORS header from the client response before copying the headers to the response writer?
You're probably right about the hackyness.
I'll have to deal with this in my proxy handler.
Thanks
Seems this middleware happily add the headers even if they're present on the response.
I'm getting this from Chrome:
The 'Access-Control-Allow-Origin' header contains multiple values 'http://localhost:8085, http://localhost:8085', but only one is allowed. Origin 'http://localhost:8085' is therefore not allowed access.