rest.CORS refuses "*" together with credentials since go-pkgz/rest#52, so the bump and the option have to land together: the option does not exist in v1.22.0 and the panic fires at construction, inside routes(), which makes it a startup failure rather than a request-time one. The wildcard stays. The comment widget is embedded on arbitrary third-party sites, so the set of origins is not knowable, which is why the escape hatch was asked for upstream instead of accepting the panic. What it costs is unchanged and now written next to the call: any site a signed-in user visits can read authenticated responses, so state-changing requests have to keep being protected by something other than the origin, X-XSRF-Token today. The example module is tidied in the same commit, as it reaches go-pkgz/rest through the replace directive and its indirect graph would otherwise keep the old pin and fail the readonly module check in CI. The bump also carries testify to v1.12.0, which drops go-spew and go-difflib from the module graph.
70 lines
2.6 KiB
AMPL
70 lines
2.6 KiB
AMPL
module github.com/umputun/remark42/backend
|
|
|
|
go 1.25.0
|
|
|
|
require (
|
|
github.com/Depado/bfchroma/v2 v2.0.0
|
|
github.com/PuerkitoBio/goquery v1.12.0
|
|
github.com/alecthomas/chroma/v2 v2.27.0
|
|
github.com/didip/tollbooth/v8 v8.0.1
|
|
github.com/go-pkgz/auth/v2 v2.1.5
|
|
github.com/go-pkgz/jrpc v0.4.0
|
|
github.com/go-pkgz/lcw/v2 v2.0.0
|
|
github.com/go-pkgz/lgr v0.12.3
|
|
github.com/go-pkgz/notify v1.3.0
|
|
github.com/go-pkgz/repeater/v2 v2.2.0
|
|
github.com/go-pkgz/rest v1.24.0
|
|
github.com/go-pkgz/routegroup v1.6.0
|
|
github.com/go-pkgz/syncs v1.3.2
|
|
github.com/golang-jwt/jwt/v5 v5.3.1
|
|
github.com/google/uuid v1.6.0
|
|
github.com/gorilla/feeds v1.2.0
|
|
github.com/jessevdk/go-flags v1.6.1
|
|
github.com/kyokomi/emoji/v2 v2.2.13
|
|
github.com/microcosm-cc/bluemonday v1.0.27
|
|
github.com/rs/xid v1.6.0
|
|
github.com/russross/blackfriday/v2 v2.1.0
|
|
github.com/skip2/go-qrcode v0.0.0-20200617195104-da1b6568686e
|
|
github.com/stretchr/testify v1.12.0
|
|
go.etcd.io/bbolt v1.5.0
|
|
go.uber.org/goleak v1.3.0
|
|
golang.org/x/crypto v0.53.0
|
|
golang.org/x/image v0.45.0
|
|
golang.org/x/net v0.56.0
|
|
golang.org/x/oauth2 v0.36.0
|
|
)
|
|
|
|
require (
|
|
cloud.google.com/go/compute/metadata v0.9.0 // indirect
|
|
github.com/andybalholm/cascadia v1.3.4 // indirect
|
|
github.com/aymerick/douceur v0.2.0 // indirect
|
|
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
|
github.com/dghubble/oauth1 v0.7.3 // indirect
|
|
github.com/dlclark/regexp2/v2 v2.2.2 // indirect
|
|
github.com/go-oauth2/oauth2/v4 v4.5.4 // indirect
|
|
github.com/go-pkgz/email v0.6.0 // indirect
|
|
github.com/go-pkgz/expirable-cache/v3 v3.1.0 // indirect
|
|
github.com/go-pkgz/repeater v1.2.0 // indirect
|
|
github.com/golang/snappy v1.0.0 // indirect
|
|
github.com/gorilla/css v1.0.1 // indirect
|
|
github.com/gorilla/websocket v1.5.3 // indirect
|
|
github.com/hashicorp/errwrap v1.1.0 // indirect
|
|
github.com/hashicorp/go-multierror v1.1.1 // indirect
|
|
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
|
|
github.com/klauspost/compress v1.18.7 // indirect
|
|
github.com/montanaflynn/stats v0.9.0 // indirect
|
|
github.com/redis/go-redis/v9 v9.21.0 // indirect
|
|
github.com/rrivera/identicon v0.0.0-20240116195454-d5ba35832c0d // indirect
|
|
github.com/slack-go/slack v0.27.0 // indirect
|
|
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
|
|
github.com/xdg-go/scram v1.2.0 // indirect
|
|
github.com/xdg-go/stringprep v1.0.4 // indirect
|
|
github.com/youmark/pkcs8 v0.0.0-20240726163527-a2c0da244d78 // indirect
|
|
go.mongodb.org/mongo-driver v1.17.9 // indirect
|
|
go.uber.org/atomic v1.11.0 // indirect
|
|
golang.org/x/sync v0.22.0 // indirect
|
|
golang.org/x/sys v0.47.0 // indirect
|
|
golang.org/x/text v0.41.0 // indirect
|
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
|
)
|