Skip to content
Back to skills

Br Cors Public Client

ASecurity

Configure better-route 0.5.0 CORS and preflight support for public REST clients. Use when adding CorsMiddleware, CorsPolicy, Router::options(), Authorization or Idempotency-Key cross-origin requests, credentialed browser clients, app clients, OPTIONS routes, or debugging failed REST preflight requests.

  • 22 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added June 5, 2026
securityphpdebuggingapi

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned June 5, 2026

npx -y skills add Lonsdale201/wp-agent-skills --skill br-cors-public-client --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Br Cors Public Client?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Br Cors Public Client
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lonsdale201-br-cors-public-client/badge)](https://www.skillsdirectory.com/skills/lonsdale201-br-cors-public-client)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: br-cors-public-client
description: Configure better-route 0.5.0 CORS and preflight support for public REST clients. Use when adding CorsMiddleware, CorsPolicy, Router::options(), Authorization or Idempotency-Key cross-origin requests, credentialed browser clients, app clients, OPTIONS routes, or debugging failed REST preflight requests.
---

# better-route: CORS and preflight

Use explicit CORS policy for browser or embedded clients. Do not rely on incidental WordPress defaults when the API needs `Authorization`, `Idempotency-Key`, `If-Match`, `X-Request-ID`, or credentials.

## Global middleware

```php
use BetterRoute\Middleware\Cors\CorsMiddleware;
use BetterRoute\Middleware\Cors\CorsPolicy;

$cors = new CorsMiddleware(new CorsPolicy(
    allowedOrigins: ['https://app.example.com'],
    allowCredentials: true
));

$router->middleware([$cors]);
```

Default allowed headers include:

- `Authorization`
- `Content-Type`
- `Idempotency-Key`
- `If-Match`
- `If-None-Match`
- `X-Request-ID`
- `X-WP-Nonce`

Default exposed headers include `ETag`, `Idempotency-Replayed`, `X-RateLimit-*`, and `X-Request-ID`.

## Explicit preflight route

`CorsMiddleware` can short-circuit `OPTIONS` requests, but the router must register an `OPTIONS` route for that path when WordPress would not otherwise dispatch it.

```php
$router->options('/account/payment-methods', static fn () => null)
    ->middleware([$cors]);
```

`Router::options()` is public by default in 0.5.0. Do not attach business handlers to preflight routes.

## Rules

- Prefer an origin allowlist. Use `*` only for non-credentialed public APIs.
- If `allowCredentials: true`, do not return wildcard origin; `CorsPolicy` echoes the allowed request origin.
- Put CORS early in the middleware list so errors and short-circuits still get headers where possible.
- Keep allowed headers aligned with actual client needs; add custom headers deliberately.
- Keep CORS separate from authentication. CORS says which browser origins may call; auth says who the caller is.

## Source refs

- `libraries/better-route/src/Middleware/Cors/CorsMiddleware.php`
- `libraries/better-route/src/Middleware/Cors/CorsPolicy.php`
- `libraries/better-route/src/Router/Router.php`
- `libraries/better-route/tests/BuiltInMiddlewareTest.php`
- `libraries/better-route/tests/RouterPipelineTest.php`

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml241 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…