mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-21 00:02:30 +00:00
docs: document the empty allowlist as deny every origin
This commit is contained in:
@@ -30302,7 +30302,7 @@ components:
|
||||
nullable: true
|
||||
items:
|
||||
type: string
|
||||
description: "Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset."
|
||||
description: "Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. An empty list allows no origin at all, blocking every browser while leaving non-browser clients unaffected. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset."
|
||||
error_handler_path:
|
||||
type: string
|
||||
description: Path to a script to run when the triggered job fails. A bare
|
||||
@@ -30399,7 +30399,7 @@ components:
|
||||
nullable: true
|
||||
items:
|
||||
type: string
|
||||
description: "Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset."
|
||||
description: "Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. An empty list allows no origin at all, blocking every browser while leaving non-browser clients unaffected. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset."
|
||||
error_handler_path:
|
||||
type: string
|
||||
description: Path to a script to run when the triggered job fails. A bare
|
||||
@@ -30503,7 +30503,7 @@ components:
|
||||
nullable: true
|
||||
items:
|
||||
type: string
|
||||
description: "Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset."
|
||||
description: "Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. An empty list allows no origin at all, blocking every browser while leaving non-browser clients unaffected. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset."
|
||||
error_handler_path:
|
||||
type: string
|
||||
description: Path to a script to run when the triggered job fails. A bare
|
||||
|
||||
Generated
+4
-2
@@ -8393,8 +8393,10 @@ properties:
|
||||
the request''s Origin header (ignoring case) and echoed back on a match. When
|
||||
set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin
|
||||
the runnable returns via wm_headers. Use [''*''] to opt out of any restriction,
|
||||
including the http_route_default_allowed_origins instance setting. When null,
|
||||
the instance setting applies, or Access-Control-Allow-Origin: * if it is unset.'
|
||||
including the http_route_default_allowed_origins instance setting. An empty
|
||||
list allows no origin at all, blocking every browser while leaving non-browser
|
||||
clients unaffected. When null, the instance setting applies, or Access-Control-Allow-Origin:
|
||||
* if it is unset.'
|
||||
error_handler_path:
|
||||
type: string
|
||||
description: Path to a script to run when the triggered job fails. A bare path,
|
||||
|
||||
@@ -69,7 +69,7 @@ export const httpTriggerRequestSchema = z.object({
|
||||
"wrap_body": z.boolean().describe("If true, wraps the request body in a 'body' parameter").optional(),
|
||||
"mode": z.enum(["enabled", "disabled", "suspended"]).describe("job trigger mode").optional(),
|
||||
"raw_string": z.boolean().describe("If true, passes the request body as a raw string instead of parsing as JSON").optional(),
|
||||
"allowed_origins": z.array(z.string()).describe("Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset.").nullable().optional(),
|
||||
"allowed_origins": z.array(z.string()).describe("Origins allowed to call this route cross-origin, matched against the request's Origin header (ignoring case) and echoed back on a match. When set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin the runnable returns via wm_headers. Use ['*'] to opt out of any restriction, including the http_route_default_allowed_origins instance setting. An empty list allows no origin at all, blocking every browser while leaving non-browser clients unaffected. When null, the instance setting applies, or Access-Control-Allow-Origin: * if it is unset.").nullable().optional(),
|
||||
"error_handler_path": z.string().describe("Path to a script to run when the triggered job fails. A bare path, without the script/ or flow/ prefix a schedule error handler takes; it cannot be a flow.").optional(),
|
||||
"error_handler_args": z.record(z.string(), z.any()).describe("Arguments to pass to the error handler").optional(),
|
||||
"retry": z.object({
|
||||
|
||||
@@ -103,8 +103,10 @@ properties:
|
||||
the request''s Origin header (ignoring case) and echoed back on a match. When
|
||||
set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin
|
||||
the runnable returns via wm_headers. Use [''*''] to opt out of any restriction,
|
||||
including the http_route_default_allowed_origins instance setting. When null,
|
||||
the instance setting applies, or Access-Control-Allow-Origin: * if it is unset.'
|
||||
including the http_route_default_allowed_origins instance setting. An empty
|
||||
list allows no origin at all, blocking every browser while leaving non-browser
|
||||
clients unaffected. When null, the instance setting applies, or Access-Control-Allow-Origin:
|
||||
* if it is unset.'
|
||||
error_handler_path:
|
||||
type: string
|
||||
description: Path to a script to run when the triggered job fails. A bare path,
|
||||
|
||||
Reference in New Issue
Block a user