Skip to content

docs: send Access-Control-Allow-Origin on every docs response - #375

Merged
thomaspinder merged 2 commits into
mainfrom
docs/cors-header
Oct 1, 2026
Merged

thomaspinder merged 2 commits into
mainfrom
docs/cors-header

Conversation

@thomaspinder

Copy link
Copy Markdown
Collaborator

Motivation

GitHub Pages sent Access-Control-Allow-Origin: * on every response. Cloudflare does not send it by default, so since the move to Cloudflare (#374) a browser blocks JavaScript on another site from reading the docs' files, for example a web tool that loads objects.inv. Nobody would report this kind of failure, because the error only shows in their own browser console.

Solution

Add docs/_headers, which Cloudflare's static assets read, and ship it to the site root next to _redirects through html_extra_path. It sets Access-Control-Allow-Origin: * on every path, as GitHub Pages did.

Verification

  • A throwaway Sphinx 9.0.4 build copies both _redirects and _headers to the output root.
  • wrangler dev (4.145.0) with this repo's docs/wrangler.jsonc and the current production build returns access-control-allow-origin: * on pages, directory URLs, objects.inv, static files and 404s. _headers itself is not served (404), and the _redirects rules still parse.
  • After the merge: the deploy job publishes it. Check with curl -sI https://impulso.quantclimate.com/objects.inv | grep -i access-control.

🤖 Generated with Claude Code

https://claude.ai/code/session_015fagcMeo1LmLG2Dg3NybmQ

GitHub Pages sent "Access-Control-Allow-Origin: *" on every response;
Cloudflare does not by default. Add a _headers file, shipped to the
site root by html_extra_path, so tools on other sites can still read
the docs' files (objects.inv, images, JSON) from a browser.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015fagcMeo1LmLG2Dg3NybmQ
@thomaspinder
thomaspinder enabled auto-merge October 1, 2026 07:00
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@thomaspinder
thomaspinder merged commit 5d01d3b into main Oct 1, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant