|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Layer: L7 Application ยท Build flags: none (core features only)
If a web app served from another origin needs to call this device's JSON API from the browser, the device must send CORS headers. set_cors(origin) builds the Access-Control-Allow-* block once and injects it into every response - and answers the CORS preflight OPTIONS request automatically.
One call enables it. Configure the policy at setup; every handler's response then carries the headers, and preflights are handled for you:
The header block is built once into CORS_HDR_BUF_SIZE and reused, so there is no per-request cost. Use a specific origin in production rather than *.
From a page on another origin: ‘fetch('http://<ip>/api’).then(r=>r.json()).then(console.log)`.
The complete sketch (CORS.ino), reproduced verbatim with added explanatory comments: