Skip to content

fix(config): honor CORS_* environment variables - #216

Draft
alukach wants to merge 2 commits into
mainfrom
fix/cors-env-vars
Draft

alukach wants to merge 2 commits into
mainfrom
fix/cors-env-vars

Conversation

@alukach

@alukach alukach commented Sep 30, 2026

Copy link
Copy Markdown
Member

The documented CORS_ALLOW_ORIGINS, CORS_ALLOW_METHODS, etc. environment variables were silently ignored: with env_nested_delimiter="_", pydantic-settings exploded CORS_ALLOW_ORIGINS into cors.allow.origins, which was dropped. Only the CORS={...} JSON form worked, so restricted origins silently stayed *. This happens with every pydantic-settings version I tried (2.10.1 through 2.14.1), not only the latest.

Changes:

  • Set env_nested_max_split=1 so CORS_ALLOW_ORIGINS maps to cors.allow_origins. ITEMS_FILTER_CLS/ARGS/KWARGS are unaffected.
  • Mark the CORS list fields NoDecode so the documented comma-separated form works, the same way root_path_skip_prefixes already does.
  • Raise the minimum to pydantic-settings>=2.8.0; 2.7.0 doesn't support env_nested_max_split, which I confirmed by testing it.

Tests cover the CORS_* form, the CORS={...} JSON form, and ITEMS_FILTER_* still parsing. test_cors_env_vars fails on main.

🤖 Generated with Claude Code

With env_nested_delimiter='_', CORS_ALLOW_ORIGINS was exploded into
cors.allow.origins and silently dropped, so restricted origins stayed
'*'. Limit nested splitting to one level and skip JSON decoding for the
comma-separated list fields. Requires pydantic-settings>=2.8.0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added the fix label Sep 30, 2026
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Claude finished @alukach's task in 12s —— View job


I'll analyze this and get back to you.


💰 Estimated review cost: $0.12 · 0m12s · 6 turns

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.74%. Comparing base (be008ba) to head (018cbb4).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #216      +/-   ##
==========================================
- Coverage   89.76%   89.74%   -0.02%     
==========================================
  Files          30       30              
  Lines        1348     1346       -2     
  Branches      180      179       -1     
==========================================
- Hits         1210     1208       -2     
  Misses         97       97              
  Partials       41       41              
Flag Coverage Δ
unittests 89.74% <100.00%> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Accepts the JSON-list env form (CORS_ALLOW_ORIGINS='["..."]') in
addition to comma-separated, matching other list settings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant