lomigmegard/akka-http-cors
65.0
Adequate · 20 September 2026
1k
lines of production code
Scala
with Java
1
measurement over time
What this system is
This system is a library that provides server-side Cross-Origin Resource Sharing (CORS) support for Akka HTTP applications. It offers both Scala and Java DSLs to configure and enforce CORS policies, including handling preflight requests, validating origins and headers, and managing custom rejections. The library integrates with the Akka configuration system for flexible settings and includes performance benchmarks to measure its overhead.
How it got here
2016 — Initial project scaffolding and setup
4 changes.
This period established the foundational structure for the akka-http-cors library, including build configuration, documentation, and initial commit history. It involved upgrading core dependencies to Akka 2.8.0 and Akka HTTP 10.5.0 while setting up cross-compilation for multiple Scala versions. The work also included implementing initial test suites for CORS directive behavior and adding JMH benchmarks to measure performance overhead.
2017–2019 — Java DSL and configuration support
11 changes.
This period focused on expanding the library's capabilities by introducing a comprehensive Java DSL for CORS configuration and handling, mirroring the existing Scala implementation. It also established a robust configuration system with default settings, ActorSystem integration, and caching, supported by new example projects and extensive test coverage.
Features
Added JMH benchmarks for Akka HTTP CORS performance
A new JMH benchmark suite has been added to measure the performance overhead of the CORS directive compared to a baseline route. The benchmark initializes an Akka HTTP server with both a standard endpoint and a CORS-enabled endpoint, then runs throughput tests for standard GET requests, CORS-preflighted requests, and simple CORS requests to quantify the impact of the CORS implementation.
akka-http-cors-bench-jmh · high confidence
Added Scala CORS server example
A new example server (CorsServer.scala) has been added to the akka-http-cors-example project, demonstrating how to configure and run an Akka HTTP server with CORS support in Scala. The example shows how to set up a route that handles CORS preflight requests, integrates with custom rejection and exception handlers, and binds to localhost:8080.
akka-http-cors-example/src/main/scala · high confidence
CORS settings can now be loaded from configuration and cached per ActorSystem
The \CorsSettings\ companion object now supports creating instances from a Typesafe Config object, a config override string, or directly from an \ActorSystem\. When loaded from an \ActorSystem\, the resulting settings are cached (up to 8 entries) to avoid repeated configuration parsing, improving performance for applications that create multiple CORS directives or actors.
akka-http-cors/src/main/scala/ch/megard/akka/http/cors/scaladsl/settings · high confidence
Initial project scaffolding and documentation
This change introduces the foundational structure for the akka-http-cors library, including the initial commit of the README, CHANGELOG, and release documentation. It establishes the build configuration with Scalafmt 3.10.7 for Scala 2.13, sets up standard gitignore rules for build artifacts, and configures git blame to ignore automated formatting commits. The documentation outlines the library's purpose as a server-side CORS implementation for Akka HTTP, provides version compatibility tables, and includes usage examples for Scala and Java.
(repo-wide) · high confidence
Java DSL model classes for CORS configuration
New Java DSL classes (HttpHeaderRange, HttpHeaderRanges, HttpOriginMatcher) are added to the ch.megard.akka.http.cors.javadsl.model package, providing Java-specific wrappers that delegate to the existing Scala implementation to allow Java users to configure CORS header and origin matching.
akka-http-cors/src/main/java · high confidence
Java DSL settings API now loads configuration from ActorSystem
The Java DSL \CorsSettings\ API now supports creating settings instances directly from an \ActorSystem\. A new \create(system: ActorSystem)\ factory method has been added, allowing users to load CORS configuration from the Actor System's configuration source, in addition to the existing methods that accept a \Config\ object or a configuration override string.
akka-http-cors/src/main/scala/ch/megard/akka/http/cors/javadsl/settings · high confidence
Java DSL support for CORS rejections and directives
The Java DSL for Akka HTTP CORS now exposes \CorsDirectives\ and \CorsRejection\ types, allowing Java users to apply CORS handling and handle specific rejection causes (such as invalid origin, method, or headers) directly within the Java API.
akka-http-cors/src/main/scala/ch/megard/akka/http/cors/javadsl · high confidence
New Java CORS server example with configuration support
A new Java example demonstrating a CORS-enabled HTTP server has been added, featuring a \CorsServer\ class that binds to localhost:8080 and handles requests via \ping\ and \pong\ routes. The example includes a dedicated \application.conf\ file for loading CORS settings (such as allowed origins) and implements custom rejection and exception handlers to ensure correct CORS headers are returned even during errors.
akka-http-cors-example/src/main/java · high confidence
New Scala DSL for CORS directives and rejection handling
The \CorsDirectives\ trait and its companion object are introduced in the \scaladsl\ package, providing the \cors()\ directive to wrap routes with CORS support. This implementation loads settings from the Actor System by default and handles preflight (OPTIONS) and simple/actual requests, including validation of origins, methods, and headers. It also cleans existing CORS-related headers from responses to actual requests and provides a \corsRejectionHandler\ to convert \CorsRejection\ instances into a 400 Bad Request response with a descriptive message.
akka-http-cors/src/main/scala/ch/megard/akka/http/cors/scaladsl · high confidence
New Scala DSL implementation for CORS handling
The library introduces a new Scala DSL (\scaladsl\) for configuring and handling CORS, implemented in new files such as \CorsRejection.scala\, \HttpOriginMatcher.scala\, and \CorsSettingsImpl.scala\. This includes support for subdomain wildcard matching in allowed origins (e.g., \\*.example.com\) and the ability to handle \Origin: null\ in simple and actual requests. The \CorsRejection\ types now provide detailed causes for CORS failures, and the settings implementation caches response headers for preflight and actual requests to improve performance.
repository · high confidence
Behavioural changes
Added default CORS configuration settings
A new \reference.conf\ file has been added to the \akka-http-cors\ module, establishing default settings for the CORS directive. This configuration allows generic HTTP requests by default, permits user credentials, and allows access from all origins (\\*\) with a default set of allowed methods (GET, POST, HEAD, OPTIONS) and headers. Users can now override these defaults in their own \application.conf\ to customize CORS behavior without modifying the library code.
akka-http-cors/src/main/resources · high confidence
Test coverage
Added tests for CORS directive behavior and configuration; Added tests for CORS settings configuration loading; Added tests for HttpOriginMatcher.
Dependencies
Upgrade to Akka 2.8.0 and Akka HTTP 10.5.0
The build configuration has been updated to use Akka 2.8.0 and Akka HTTP 10.5.0, replacing previous versions. This change aligns the project with the latest Akka releases, which were originally released under the Business Source License (BSL) and are scheduled to convert to Apache 2.0 in early 2026. The \build.sbt\ file also sets the primary Scala version to 2.13.18 and enables cross-compilation for Scala 2.12.21 and Scala 3.3.7.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 65.
Lenses
- Code Health 100
- Architecture 66
- Maturity 59
- Readiness 67
- Security 75
Changes since last survey
- 300 commits — 295 feature/other, 5 fixes
By area
- (repo) — 129 commits
- (root) — 102 commits
- project/build.properties — 33 commits
- project/plugins.sbt — 28 commits
- .github/workflows — 4 commits
- akka-http-cors/src — 3 commits
- akka-http-cors-example/src — 1 commit
Notable commits
- fix: Fix CI
- fix: Fix Travis build.
- fix: Revert commit(s) 32a9225
- fix: Revert commit(s) e4d0e2e
- fix: Revert commit(s) f8d3685
- change: Add 'Reformat with scalafmt 3.10.3' to .git-blame-ignore-revs
- change: Add 'Reformat with scalafmt 3.10.4' to .git-blame-ignore-revs
- change: Add 'Reformat with scalafmt 3.7.11' to .git-blame-ignore-revs
- change: Add comment about akka version
- change: Add licence headers
- change: CI use Temurin and build against Java 17.
- change: Cleanup scalac and javac options.
- change: Mention the Apache Pekko fork
- change: Merge branch 'master' into update/akka-http-10.2.3
- change: Merge branch 'master' into update/akka-http-10.2.4
- change: Merge branch 'master' into update/akka-stream-2.6.18
- change: Merge branch 'master' into update/akka-stream-2.6.18
- change: Merge branch 'master' into update/sbt-jmh-0.4.8
- change: Merge branch 'master' into update/sbt-scalafmt-2.5.2
- change: Merge branch 'master' into update/scala-library-2.12.13
- …and 280 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
lomigmegard/akka-http-cors was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 796aac54f602f7fb65b6a77e2825c19061acbc7f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.