Skip to content

docs(server): cross-origin hosting works via cors.allowed-origins - #15

Merged
everpcpc merged 1 commit into
mainfrom
docs/cors-cross-origin
Oct 3, 2026
Merged

everpcpc merged 1 commit into
mainfrom
docs/cors-cross-origin

Conversation

@everpcpc

@everpcpc everpcpc commented Oct 3, 2026

Copy link
Copy Markdown
Member

What

The server/webui notes claimed cross-origin hosting is not supported because KMServer parsed KOMGA_CORS_ALLOWEDORIGINS without applying CORS headers. That gap is fixed in kmworks/kmrs#131, so the note is stale.

How

Reword the bullet: cross-origin hosting works once the UI's origin is listed in cors.allowed-origins, and the wildcard * is rejected because credentialed requests are always allowed.

Testing

pnpm typecheck && pnpm exec nimbus-docs check && pnpm lint:docs && pnpm build all pass locally.

KMServer now applies the configured origins as actual CORS headers
(kmworks/kmrs#131), so the note claiming cross-origin hosting is
unsupported is stale. Document that the wildcard is rejected because
credentialed requests are always allowed.
@everpcpc
everpcpc marked this pull request as ready for review October 3, 2026 00:50
@everpcpc
everpcpc merged commit cfb2768 into main Oct 3, 2026
1 check passed
@everpcpc
everpcpc deleted the docs/cors-cross-origin branch October 3, 2026 00:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant