fix(platform): DSPX-4207 align server.cors defaults with OpenTDF platform config - #199
Conversation
…form config Update the platform chart's default server.cors.allowedheaders and allowedmethods to match the OpenTDF platform's built-in CORS defaults (service/internal/server/server.go and opentdf-example.yaml): - add PATCH to allowedmethods - expand allowedheaders to Accept, Accept-Encoding, Authorization, Connect-Protocol-Version, Content-Length, Content-Type, Dpop, X-CSRF-Token, X-Requested-With, X-Rewrap-Additional-Context This lets browser clients such as the DSP Secure Viewer work with the chart defaults (notably X-Rewrap-Additional-Context) without downstream charts re-declaring the full CORS block. README regenerated via helm-docs. Signed-off-by: Jp Ayyappan <jp.ayyappan@virtru.com> Co-authored-by: CoopAgent <coopagent@users.noreply.github.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe platform Helm chart now allows ChangesPlatform chart CORS
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🤖 I have created a release *beep* *boop* --- ## [0.16.0](platform-0.15.0...platform-0.16.0) (2026-08-03) ### Bug Fixes * **platform:** DSPX-4207 align server.cors defaults with OpenTDF platform config ([#199](#199)) ([4fbf4d4](4fbf4d4)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com> Co-authored-by: Jp Ayyappan <108297634+jp-ayyappan@users.noreply.github.com> Co-authored-by: CoopAgent <coopagent@users.noreply.github.com>
What
Update the platform chart's default
server.corsvalues to match the OpenTDF platform's built-in CORS defaults:allowedmethods: addPATCH→GET, POST, PATCH, PUT, DELETE, OPTIONSallowedheaders: expand toAccept, Accept-Encoding, Authorization, Connect-Protocol-Version, Content-Length, Content-Type, Dpop, X-CSRF-Token, X-Requested-With, X-Rewrap-Additional-ContextREADME.mdregenerated via helm-docs (also picks up the stale0.15.0version badge).Why
The chart's default
allowedheaders/allowedmethodshad drifted from the platform binary's own defaults. In particular the chart was missingX-Rewrap-Additional-Context(and other browser headers), which the platform ships by default.Source of truth for the new defaults:
service/internal/server/server.go(AllowedHeaders/AllowedMethodsstruct defaults)opentdf-example.yamlserver.corsThis lets browser clients such as the Virtru DSP Secure Viewer get working CORS from the chart defaults, so downstream charts no longer need to re-declare the entire
server.corsblock.Notes
Chart.yaml/CHANGELOG.mdbump — release-please owns versioning.server.cors.enableddefault is unchanged (false); enabling CORS and settingallowedoriginsremains a per-deployment concern.Related
Summary by CodeRabbit
PATCHrequests.0.15.0.