Cors class final

Answers the cross-origin questions a browser asks before it will hand a response to JavaScript.

final app = Router()
  ..layer(Cors(origins: AllowedOrigins.only({'https://app.example'})))
  ..merge(routes);

Two kinds of request arrive. A preflight is OPTIONS carrying Access-Control-Request-Method; it is answered here and the handler never runs, because the browser is asking permission rather than making the call. Everything else runs normally and gets the allow headers added.

Put it at the top of the router. A layer below the one that rejects a request never runs, and a 401 without CORS headers reaches the browser as an opaque network error rather than as "you are not signed in".

Implemented types

Constructors

Cors({AllowedOrigins origins = const AllowedOrigins.any(), Set<String> methods = const {'GET', 'POST', 'PUT', 'PATCH', 'DELETE', 'OPTIONS'}, Set<String> headers = const {'accept', 'authorization', 'content-type'}, Set<String> exposeHeaders = const {}, bool credentials = false, Duration? maxAge})
Allows origins, with the usual defaults for everything else.

Properties

credentials → bool
Whether cookies and Authorization may be sent.
final
exposeHeaders → Set<String>
Which response headers JavaScript may read beyond the safelisted ones.
final
hashCode → int
The hash code for this object.
no setterinherited
headers → Set<String>
Which request headers a preflight may ask for.
final
maxAge → Duration?
How long a browser may cache the preflight answer.
final
methods → Set<String>
Which methods a preflight may ask for.
final
origins → AllowedOrigins
Which origins may call.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toMiddleware() → Middleware
Builds the shelf middleware this value configures.
override
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited