docs: document the empty allowlist as deny every origin

This commit is contained in:
hugocasa
2026-08-28 18:05:41 +02:00
parent bfd3769ef4
commit 1b85a271a7
4 changed files with 12 additions and 8 deletions
+4 -2
View File
@@ -8393,8 +8393,10 @@ properties:
the request''s Origin header (ignoring case) and echoed back on a match. When
set, the list governs both the preflight and the response, overriding any Access-Control-Allow-Origin
the runnable returns via wm_headers. Use [''*''] to opt out of any restriction,
including the http_route_default_allowed_origins instance setting. When null,
the instance setting applies, or Access-Control-Allow-Origin: * if it is unset.'
including the http_route_default_allowed_origins instance setting. An empty
list allows no origin at all, blocking every browser while leaving non-browser
clients unaffected. When null, the instance setting applies, or Access-Control-Allow-Origin:
* if it is unset.'
error_handler_path:
type: string
description: Path to a script to run when the triggered job fails. A bare path,