Skip to content

feat(tsa): CORS configurable pour l'API HTTP, activé pour demo.open-eidas.eu - #7

Merged
PhilippeVienne merged 1 commit into
devfrom
feat/cors-tsa-api
Sep 13, 2026
Merged

PhilippeVienne merged 1 commit into
devfrom
feat/cors-tsa-api

Conversation

@PhilippeVienne

Copy link
Copy Markdown
Contributor

Résumé

  • Ajoute OPENEIDAS_CORS_ALLOWED_ORIGIN (oe-config, oe-httpapi) : restreint Access-Control-Allow-Origin à une origine unique sur le routeur HTTP de tsa-server. Absent/vide par défaut (pas de CORS), sans impact sur les déploiements existants.
  • Expose tsa.corsAllowedOrigin dans le chart Helm, activé dans values-staging.yaml pour https://demo.open-eidas.eu (démo web à venir, GitHub Pages, dans le repo séparé open-eidas/demo).

Plan de test

  • cargo test -p oe-config -p oe-httpapi (nouveaux tests : lecture de la variable, en-tête CORS présent seulement si configuré et reflétant exactement l'origine)
  • cargo clippy --workspace --all-targets -- -D warnings, cargo fmt --check
  • CI verte

…idas.eu

Ajoute OPENEIDAS_CORS_ALLOWED_ORIGIN (oe-config, oe-httpapi) : quand
définie, une couche CORS restreint Access-Control-Allow-Origin à cette
seule origine sur le routeur HTTP de tsa-server. Vide/absent par défaut,
sans effet sur les déploiements existants.

Expose tsa.corsAllowedOrigin dans le chart Helm et l'active dans
values-staging.yaml pour https://demo.open-eidas.eu (la démo web à venir,
hébergée sur GitHub Pages), seule origine autorisée à appeler l'API de
staging depuis un navigateur.
Copilot AI lite review requested due to automatic review settings September 13, 2026 07:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Validate configured origins and add negative-origin and POST preflight coverage.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds configurable single-origin CORS support to the TSA HTTP API, enabled for the staging demo deployment.

Changes:

  • Adds OPENEIDAS_CORS_ALLOWED_ORIGIN configuration.
  • Applies CORS middleware to the HTTP router.
  • Updates Helm values and adds integration coverage.
File summaries
File Summary
deploy/helm/open-eidas/values.yaml Defines the default CORS setting.
deploy/helm/open-eidas/values-staging.yaml Enables the staging demo origin.
deploy/helm/open-eidas/templates/tsa/deployment.yaml Injects the CORS environment variable.
crates/oe-httpapi/tests/end_to_end.rs Tests configured CORS behavior.
crates/oe-httpapi/src/lib.rs Configures the CORS middleware.
crates/oe-httpapi/Cargo.toml Enables the CORS feature.
crates/oe-crosstsa/tests/against_local_server.rs Updates test router options.
crates/oe-config/src/lib.rs Loads and tests the new setting.
bin/tsa-server/src/main.rs Passes configuration to the router.
Review details

Suppressed comments (3)

crates/oe-config/src/lib.rs:179

  • This new user-facing environment variable is missing from the TSA configuration table in docs/API.md (which currently documents the other OPENEIDAS_* settings and their defaults). Please document its empty/absent default and the exact-origin behavior so non-Helm operators can discover and configure it.
            cors_allowed_origin: env::var("OPENEIDAS_CORS_ALLOWED_ORIGIN")
                .ok()
                .filter(|s| !s.is_empty()),

crates/oe-httpapi/src/lib.rs:71

  • The web demo's JSON POST /api/v1/timestamp will trigger a CORS preflight, but the new test only exercises a simple GET. Add an OPTIONS request with Access-Control-Request-Method: POST and Access-Control-Request-Headers: content-type so regressions in these allow_methods/allow_headers settings cannot leave the browser integration broken while the test still passes.
                    .allow_methods([axum::http::Method::GET, axum::http::Method::POST])
                    .allow_headers([axum::http::header::CONTENT_TYPE]),

crates/oe-httpapi/tests/end_to_end.rs:209

  • The integration test only performs GETs from the allowed origin. It does not verify that a different origin is rejected or exercise the browser preflight required for POST requests with a non-safelisted Content-Type; a regression in the single-origin check or allow_methods/allow_headers could therefore pass while the demo cannot call the API. Add negative-origin and OPTIONS preflight assertions.
    let resp = reqwest::Client::new()
        .get(format!("http://{addr}/api/v1/policy"))
        .header("Origin", "https://demo.open-eidas.eu")
        .send()
        .await
  • Files reviewed: 9/9 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +65 to +69
if let Some(origin) = opts.cors_allowed_origin.as_deref() {
if let Ok(origin) = axum::http::HeaderValue::from_str(origin) {
router = router.layer(
tower_http::cors::CorsLayer::new()
.allow_origin(origin)
@PhilippeVienne
PhilippeVienne merged commit 2d97c3c into dev Sep 13, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants