Skip to content

Do not duplicate headers #45

Description

@oliverjanik

Seems this middleware happily add the headers even if they're present on the response.

I'm getting this from Chrome:
The 'Access-Control-Allow-Origin' header contains multiple values 'http://localhost:8085, http://localhost:8085', but only one is allowed. Origin 'http://localhost:8085' is therefore not allowed access.

Activity

  1. rs commented on Jan 9, 2018

    @rs
    Owner

    Those headers are added using the Header.Set method that is supposed to replace any existing occurrence of the header. Are you sure that the other thing adding this header does not happen after cors handler? Be aware that the cors handler will add those headers before entering your handler, not after.

  2. oliverjanik commented on Jan 9, 2018

    @oliverjanik
    Author

    So if CORS handler wraps another handler, it will set these before the other handler is even run?

    The actual use case I'm working on is CORS handler wrapping reverse proxy. And sometimes the responses from upstream return CORS headers by themselves and I see duplicates.

    Wouldn't it be better to add CORS headers after the wrapped handler finishes?

  3. rs commented on Jan 9, 2018

    @rs
    Owner

    After the handler is gonna be too late: headers and body are already sent.

  4. oliverjanik commented on Jan 10, 2018

    @oliverjanik
    Author

    You're right, that seems like a shortcoming of go's handler design. I guess there' not much this library can do.

  5. oliverjanik commented on Jan 11, 2018

    @oliverjanik
    Author

    Actually I stumbled upon this solution: https://stackoverflow.com/a/38335233/177591

    Where they provide ResponseWriter implementation that let's them inject headers just before WriteHeader call.

    Your thoughts @rs?

  6. rs commented on Jan 11, 2018

    @rs
    Owner

    I know this solution but it's quite hacky. The example provided will hide the optional interfaces implemented by the ResponseWriter like Flusher, Hijacker or Pusher. There are some tricks to expose them but I don't think it's worth it for this package.

    For your proxy issue, why don't you just cleanup the CORS header from the client response before copying the headers to the response writer?

  7. oliverjanik commented on Jan 11, 2018

    @oliverjanik
    Author

    You're probably right about the hackyness.

    I'll have to deal with this in my proxy handler.

    Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions