Skip to content
CAI
Software that uses CAICheck a score

lomigmegard/akka-http-cors

65.0

Adequate · 20 September 2026

1k

lines of production code

Scala

with Java

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a library that provides server-side Cross-Origin Resource Sharing (CORS) support for Akka HTTP applications. It offers both Scala and Java DSLs to configure and enforce CORS policies, including handling preflight requests, validating origins and headers, and managing custom rejections. The library integrates with the Akka configuration system for flexible settings and includes performance benchmarks to measure its overhead.

How it got here

2016 — Initial project scaffolding and setup

4 changes.

This period established the foundational structure for the akka-http-cors library, including build configuration, documentation, and initial commit history. It involved upgrading core dependencies to Akka 2.8.0 and Akka HTTP 10.5.0 while setting up cross-compilation for multiple Scala versions. The work also included implementing initial test suites for CORS directive behavior and adding JMH benchmarks to measure performance overhead.

2017–2019 — Java DSL and configuration support

11 changes.

This period focused on expanding the library's capabilities by introducing a comprehensive Java DSL for CORS configuration and handling, mirroring the existing Scala implementation. It also established a robust configuration system with default settings, ActorSystem integration, and caching, supported by new example projects and extensive test coverage.

Features

Added JMH benchmarks for Akka HTTP CORS performance

A new JMH benchmark suite has been added to measure the performance overhead of the CORS directive compared to a baseline route. The benchmark initializes an Akka HTTP server with both a standard endpoint and a CORS-enabled endpoint, then runs throughput tests for standard GET requests, CORS-preflighted requests, and simple CORS requests to quantify the impact of the CORS implementation.

akka-http-cors-bench-jmh · high confidence

Added Scala CORS server example

A new example server (CorsServer.scala) has been added to the akka-http-cors-example project, demonstrating how to configure and run an Akka HTTP server with CORS support in Scala. The example shows how to set up a route that handles CORS preflight requests, integrates with custom rejection and exception handlers, and binds to localhost:8080.

akka-http-cors-example/src/main/scala · high confidence

CORS settings can now be loaded from configuration and cached per ActorSystem

The \CorsSettings\ companion object now supports creating instances from a Typesafe Config object, a config override string, or directly from an \ActorSystem\. When loaded from an \ActorSystem\, the resulting settings are cached (up to 8 entries) to avoid repeated configuration parsing, improving performance for applications that create multiple CORS directives or actors.

akka-http-cors/src/main/scala/ch/megard/akka/http/cors/scaladsl/settings · high confidence

Initial project scaffolding and documentation

This change introduces the foundational structure for the akka-http-cors library, including the initial commit of the README, CHANGELOG, and release documentation. It establishes the build configuration with Scalafmt 3.10.7 for Scala 2.13, sets up standard gitignore rules for build artifacts, and configures git blame to ignore automated formatting commits. The documentation outlines the library's purpose as a server-side CORS implementation for Akka HTTP, provides version compatibility tables, and includes usage examples for Scala and Java.

(repo-wide) · high confidence

Java DSL model classes for CORS configuration

New Java DSL classes (HttpHeaderRange, HttpHeaderRanges, HttpOriginMatcher) are added to the ch.megard.akka.http.cors.javadsl.model package, providing Java-specific wrappers that delegate to the existing Scala implementation to allow Java users to configure CORS header and origin matching.

akka-http-cors/src/main/java · high confidence

Java DSL settings API now loads configuration from ActorSystem

The Java DSL \CorsSettings\ API now supports creating settings instances directly from an \ActorSystem\. A new \create(system: ActorSystem)\ factory method has been added, allowing users to load CORS configuration from the Actor System's configuration source, in addition to the existing methods that accept a \Config\ object or a configuration override string.

akka-http-cors/src/main/scala/ch/megard/akka/http/cors/javadsl/settings · high confidence

Java DSL support for CORS rejections and directives

The Java DSL for Akka HTTP CORS now exposes \CorsDirectives\ and \CorsRejection\ types, allowing Java users to apply CORS handling and handle specific rejection causes (such as invalid origin, method, or headers) directly within the Java API.

akka-http-cors/src/main/scala/ch/megard/akka/http/cors/javadsl · high confidence

New Java CORS server example with configuration support

A new Java example demonstrating a CORS-enabled HTTP server has been added, featuring a \CorsServer\ class that binds to localhost:8080 and handles requests via \ping\ and \pong\ routes. The example includes a dedicated \application.conf\ file for loading CORS settings (such as allowed origins) and implements custom rejection and exception handlers to ensure correct CORS headers are returned even during errors.

akka-http-cors-example/src/main/java · high confidence

New Scala DSL for CORS directives and rejection handling

The \CorsDirectives\ trait and its companion object are introduced in the \scaladsl\ package, providing the \cors()\ directive to wrap routes with CORS support. This implementation loads settings from the Actor System by default and handles preflight (OPTIONS) and simple/actual requests, including validation of origins, methods, and headers. It also cleans existing CORS-related headers from responses to actual requests and provides a \corsRejectionHandler\ to convert \CorsRejection\ instances into a 400 Bad Request response with a descriptive message.

akka-http-cors/src/main/scala/ch/megard/akka/http/cors/scaladsl · high confidence

New Scala DSL implementation for CORS handling

The library introduces a new Scala DSL (\scaladsl\) for configuring and handling CORS, implemented in new files such as \CorsRejection.scala\, \HttpOriginMatcher.scala\, and \CorsSettingsImpl.scala\. This includes support for subdomain wildcard matching in allowed origins (e.g., \\*.example.com\) and the ability to handle \Origin: null\ in simple and actual requests. The \CorsRejection\ types now provide detailed causes for CORS failures, and the settings implementation caches response headers for preflight and actual requests to improve performance.

repository · high confidence

Behavioural changes

Added default CORS configuration settings

A new \reference.conf\ file has been added to the \akka-http-cors\ module, establishing default settings for the CORS directive. This configuration allows generic HTTP requests by default, permits user credentials, and allows access from all origins (\\*\) with a default set of allowed methods (GET, POST, HEAD, OPTIONS) and headers. Users can now override these defaults in their own \application.conf\ to customize CORS behavior without modifying the library code.

akka-http-cors/src/main/resources · high confidence

Test coverage

Added tests for CORS directive behavior and configuration; Added tests for CORS settings configuration loading; Added tests for HttpOriginMatcher.

Dependencies

Upgrade to Akka 2.8.0 and Akka HTTP 10.5.0

The build configuration has been updated to use Akka 2.8.0 and Akka HTTP 10.5.0, replacing previous versions. This change aligns the project with the latest Akka releases, which were originally released under the Business Source License (BSL) and are scheduled to convert to Apache 2.0 in early 2026. The \build.sbt\ file also sets the primary Scala version to 2.13.18 and enables cross-compilation for Scala 2.12.21 and Scala 3.3.7.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 65.

Lenses

  • Code Health 100
  • Architecture 66
  • Maturity 59
  • Readiness 67
  • Security 75

Changes since last survey

  • 300 commits — 295 feature/other, 5 fixes

By area

  • (repo) — 129 commits
  • (root) — 102 commits
  • project/build.properties — 33 commits
  • project/plugins.sbt — 28 commits
  • .github/workflows — 4 commits
  • akka-http-cors/src — 3 commits
  • akka-http-cors-example/src — 1 commit

Notable commits

  • fix: Fix CI
  • fix: Fix Travis build.
  • fix: Revert commit(s) 32a9225
  • fix: Revert commit(s) e4d0e2e
  • fix: Revert commit(s) f8d3685
  • change: Add 'Reformat with scalafmt 3.10.3' to .git-blame-ignore-revs
  • change: Add 'Reformat with scalafmt 3.10.4' to .git-blame-ignore-revs
  • change: Add 'Reformat with scalafmt 3.7.11' to .git-blame-ignore-revs
  • change: Add comment about akka version
  • change: Add licence headers
  • change: CI use Temurin and build against Java 17.
  • change: Cleanup scalac and javac options.
  • change: Mention the Apache Pekko fork
  • change: Merge branch 'master' into update/akka-http-10.2.3
  • change: Merge branch 'master' into update/akka-http-10.2.4
  • change: Merge branch 'master' into update/akka-stream-2.6.18
  • change: Merge branch 'master' into update/akka-stream-2.6.18
  • change: Merge branch 'master' into update/sbt-jmh-0.4.8
  • change: Merge branch 'master' into update/sbt-scalafmt-2.5.2
  • change: Merge branch 'master' into update/scala-library-2.12.13
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

lomigmegard/akka-http-cors was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 796aac54f602f7fb65b6a77e2825c19061acbc7f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.