{"_id":"@ampproject/toolbox-cors","_rev":"59-4bbfe490edd4e5fed33c01a7d41902b6","name":"@ampproject/toolbox-cors","description":"An express middleware implementing the AMP CORS protocol","dist-tags":{"beta":"1.1.0-beta.0","alpha":"2.7.0-alpha.1","canary":"3.0.0-canary.2","latest":"2.10.1"},"versions":{"1.0.0-beta.0":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"choumx","email":"willchou@google.com"},{"name":"sepandparhami","email":"sparhami@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"17c4d05d19e65359eb3e4c36a47babdbcafacbcd","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.0.tgz","fileCount":4,"integrity":"sha512-CO7Q47aSCdHDBGjer7Ve05XeS8wlTTHKtj5I1QwOsQHckw0dCXKU9O7j5lek/lGzKIwebymvIziRt3CIAg6Unw==","signatures":[{"sig":"MEQCIA/+pcXxd3bw2qIEyfaJiU9IgHm98WQiLWuf3fTzI7bQAiBDQr9FunJpKrwlHnGtkuKmqoVTn5aQKxkY5982TU1XDA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":10734,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc/p+NCRA9TVsSAnZWagAAYwIQAIgC/xFUieGjMku5ZCDO\niNtik0V/gZXiM2pg8eM556FDl+Hm4Rj7CXjDoG/hVEhK1MDW0rqEV3TKJBLA\n7uUFqTsqNis6jdFVQrce/IeGD+H7/J7+Tj4zqBYHambHPHfPhKeTU45BqjeW\nH4IMuFAR22rJI2vOONruMQVN7bTB/RansEfWpMP9nXwNHkPnQ7kfkyID+kfr\nvx6eR7kYuYCUJHHfacAg30++znr4ot0EXE3RgUp2UTwe0hfk8j/EddI56phL\n0umXYMMWR8y1shFGlK02bwmKasB/mGil/2EXgDTKFUMfibBE/ibIgSGVyHT8\np6sOCOqNZI+EWLpBMfRofZh7RWEA3V4n+i95X9hJQk2Bl3A5RQrBdppumG+m\ntMXgfO/fV64U1CXO3VJQ/XEh2NwYeD33j4Id+A3iWrXda4bt8T8blcgiKSM5\nrtcwB8yA85ogBAIk/GUY3h3CpF50srEaVw8uAd6ZYKMI/aTYbTBnjTA898b2\nvHnL9SlzZHRcWjqY41riPPnoY+BDqxlOTBM7W+a1jPg0zWZ+vBFThUvncyNq\ng1vd8Lf2G2I4ZZVJMrDNaZGlDkBtcA1GiVY0XKwkYBvjphSbQfXNXQdCvlFQ\n3BZFfn/RISKIfB9KoY9QMAacK1dIT3ZKjJN5LOC3A4ugFAUrOf6C76EHDFLh\njquZ\r\n=3Qwh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"68bce56d4878ace45b6573824a56656667db5c85","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"6.9.0","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.0","@ampproject/toolbox-cache-url":"^1.0.0-beta.0","@ampproject/toolbox-cache-list":"^1.0.0-beta.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.0_1560190860629_0.45366264704263193","host":"s3://npm-registry-packages"}},"1.0.0-beta.2":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.2","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.2","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"3d0e29ef8319cd6f29bb424cb33e5980c63b823b","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.2.tgz","fileCount":5,"integrity":"sha512-TgdstSUOARYm323w0U5XItj9P1MGvKiHMeeIXpJJCfGuFMbWEDTbjDvAYiszkJAH5qVb65++9cmWntL/KV6yrA==","signatures":[{"sig":"MEUCIB0UhuLguxU1zaN0FvE7KzFg9Xr2OJDOFRzapDKP95VSAiEAqRwEx4i4wz/rwbkpYzDnendv6gIgEuFPiz1nQ3Gb8iA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdC1SoCRA9TVsSAnZWagAAe8oP/RrlqWoTBcDGj8rmebxT\nCa2sLdlD2H7BCuWSZbK5aPDKXwtgF8Tnvj8ncFnOmJhFPW8mMAupr02MFIxF\n8pNuIYYkhe6jG9kPqY8YqelNcz4mRvWBuObRr+EkxFkpyn0SKV7Aahwcw51i\npxkkT+HiDf/n8T320gd0ddKP5EYu4lyF/v5vAVbvyGy5C9XDCujYmUlz/+GC\nuKtgN2JI7zQG/Z2Ns9Lpx+pT+rYQDEDDb/+dhAnL+XFKB0cZeMn42iuy0Hvw\nfTwWJ65QOrHS+K8ogYaw464SczJgo0gJ0CruYUKTQzRfa+VpbqVPkXP4uS8L\nlrE83y2fUb0fPhMlfGZWlCc58cdU21Do87Fqzeaot9eKFL3SiG02b5feMEMs\nGWgO0R2aVFYkuGzkjQ1/xqUz5v6/6zUm/eK/yDAMJeCGw1rdCAe9kAv8m8rV\nNEddJ2A2MIb9B/ltn3Y/6vmHfKOHkalw8O1oj/L9p58CxnH7VMTDULEqFl36\n7QFHoLagbyZ3uaKRhcPOrRbUE4HGaeT+6UX1j6jBnZaKNgTXLha4sjPZHhk8\nH4cSPJxCRRYGdWIuJIZf3Dfqi+Sq2yzIuqYwZvP4bO56VLS9r3Zl3t3xDF+j\nYmuMUDKwVxLpGztTCy9m2aZhvJwBgg+MFD/DfL7713h2kvHUIqe4TAGXGV3j\n9uSC\r\n=o2En\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://www.ampproject.org/docs/fundamentals/amp-cors-requests) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@beta --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://ampbyexample.com` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json (with the addition of `bing-amp.com`). All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://www.ampproject.org/docs/reference/components/amp-form#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// => Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin instead of \n// Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin, AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://ampbyexample-com.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://ampbyexample-com.cdn.ampproject.org\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nX-Powered-By: Express\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"fa3197ef68f96c516511d8cd97f30dd06a342553","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.15.0/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.2","@ampproject/toolbox-cache-url":"^1.0.0-beta.2","@ampproject/toolbox-cache-list":"^1.0.0-beta.2"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.2_1561023655830_0.550235915506583","host":"s3://npm-registry-packages"}},"1.0.0-beta.3":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.3","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.3","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"ac92126068012c80eb2fd5c0f53e236624f60ee5","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.3.tgz","fileCount":5,"integrity":"sha512-frxX8OzbzQGYmMY0RLhaHm6dc0TD0xMTRcSMkQCzM7+Lpl2QHKf1Yum17Qzqe5pqGsDilSfveev0BgytoV4Xjw==","signatures":[{"sig":"MEQCIBIo283K73RZ3vtHym59CoTGWRzhjABXSm0vqhoE1y6yAiBnTj5y3/P0EZ3OX7Usfs/AN6A81u9y2PIH83FtyZABMQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22082,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdC1bfCRA9TVsSAnZWagAA2HgP/1vXvlTyuPOwQDQ+PGo4\nCoEgF7lk6HDp2SY/63LHtcwDNQT/7cgafXGf+fMmrfY6AhDlU4stNy1UwQK3\nvDeTzhcjI2XKvdyLLLEq2tCdUDXjXwYJnS737RSkqJE0OYcPw8M+dqJcd585\nmMy46L/26iHIZZYnU3nIuD8xyKDwjx3r9SZ8ZkXVFIEd80Tn9BIIaR5aBqOO\nEdyKQ0Wtkxbb2zVqRWuWOxbu3PQN13PqgxwsLQDiY6YbuXDToU9V+7ULygQW\nIC4XJ2NZuFk6vt2ymYJGeW072njEn0UNlkaWUTPieDXMkju+443FZF4EA7FQ\nmQ3I85xfgNg6amY2gqqRLdRVDS7mhkin+YWbUnQS7YF6E/ln4XqmomU+CPCx\nRv8e0vFxxLRQ2IRS5VNQPpOg4U0UYh0732NSpXSTvsw3hRaH3yeRoUjEXg2o\ngkPyYqzSs/uXWA8U73VhGyatpv0cBiPNLU03fTvkcf4qwfMZSHvoukZtzCHS\n2oVt2uiSTtW+n+hP5An8wVWg97+yMrL5TawpnfNmSdJLdQhxE2Et5Hdsw3d9\n0Q9GfAl3pC3XQAVu0PnvQcCN5ve+Obe62I8C0jxxFID0I8F79KN0rsniz/ls\n9Ce6FJTyCzCPEGC4PSuwxm+pqjQtEoA87zdmFSf/JXLOEHInyWhr6keMpYkG\nAV/q\r\n=Txn0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://www.ampproject.org/docs/fundamentals/amp-cors-requests) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@beta --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://ampbyexample.com` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json (with the addition of `bing-amp.com`). All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://www.ampproject.org/docs/reference/components/amp-form#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// => Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin instead of \n// Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin, AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://ampbyexample-com.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://ampbyexample-com.cdn.ampproject.org\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nX-Powered-By: Express\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"182e821deefc39940858ab46912e55f1f3da59f5","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.15.0/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.3","@ampproject/toolbox-cache-url":"^1.0.0-beta.3","@ampproject/toolbox-cache-list":"^1.0.0-beta.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.3_1561024222697_0.09456699053581841","host":"s3://npm-registry-packages"}},"1.0.0-beta.4":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.4","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.4","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"21089f3475f9b7048dcee572bce5ee17739e1b52","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.4.tgz","fileCount":4,"integrity":"sha512-7YyQcfOWABnZEI0FfDIS+HO++zzan597wzGHsW0zoWvzBRPil1rAIH54tQDCljYWSktm/IcsdpuBWNPc8bEtbA==","signatures":[{"sig":"MEQCIA30wiM0nSNMD3P13ty08//53sSYqEjE4uxcQnNWy4VMAiB1TiuZ85HDdcNwLsXSxjB+z+/aGKlejxFZixQV+1QkbQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":10741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdJ0nWCRA9TVsSAnZWagAAhoMP/2m0DEjS6dhrH+oTywLm\nfHgDAERDhd63qKQwwgZYVoAmfnqb2d9T4kRGg8IgZ7v48yfj1n7nhHjL2DhY\nRrdnmexvdcqy5mVBzDTNBmGp8qWTPrLkHfuqYDpmgRzIoqW1CLf7pZ2CKPMK\nOtraLA3olPHSsL9TzKkN2gbIbF5oEPxr90116GsfFs5GP3YCt3+4Zgpj8X/f\naXh5CBW1psuhSghb4LFBn/pi86c99BzHGUUrqvLDMxRfW5Bp9K3AtD2XoAfw\niZSIJL7OGDBQUQXKFhvJvHNl9cY9O3eppejjed3jX53BQCQqzqJYDMG6Kz8H\nPyAVJCnDPNUv+YV95SfBM069nEIKdw3BtRjupIerqnH9hLgMCT9F6MJw+bhZ\ndN2YAP4OeQYF5savKRBYHh+3b3TG+2i33prRu5QCFFcoYvxx0/5GFG+qrJCy\nxTfkMzNL80G6xylOPcgTxptRDo7FQRFaciI0Yv9F24xgh8ZiH3AqPHecpJt2\noA2GdBAU2zQbACkEqFGgPyeln5iHRE4D298T4yJf0A4I5IOo8PKeuzHlIOVF\n6ImadRHAQcs9+eBy7QlBM2L5EM/J20pFSMwz5PdveJgibHSBmksbHxHBMtTe\nZBLwA+eJZ/93aeD30qZRj15KRMgHU6/rj2AsSQebmh2+zEm0RtJijnJQOXXi\nAtSW\r\n=lQLc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://www.ampproject.org/docs/fundamentals/amp-cors-requests) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@canary --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://ampbyexample.com` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json (with the addition of `bing-amp.com`). All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://www.ampproject.org/docs/reference/components/amp-form#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// => Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin instead of \n// Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin, AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://ampbyexample-com.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://ampbyexample-com.cdn.ampproject.org\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nX-Powered-By: Express\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"cb496f081c871a25dc73113ae1e1fccfb59b2732","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"6.9.0","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.4","@ampproject/toolbox-cache-url":"^1.0.0-beta.4","@ampproject/toolbox-cache-list":"^1.0.0-beta.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.4_1562855893706_0.48471700202305845","host":"s3://npm-registry-packages"}},"1.0.0-beta.5":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.5","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.5","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"bad611dfbc64a77710dd4bc667b11dd918c23a3a","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.5.tgz","fileCount":5,"integrity":"sha512-7XIvMMocJZA/gF9vHipEDMYWBtvwMosOMKhvscmaE2b7oG7SA34rJ2Jj5Nr9b0j8UUOmU09TIteLjaHfZNvEbA==","signatures":[{"sig":"MEUCIFgS50R9Mb479cwiyLH7GCcBU02O+4cAOO2/BMG6NuZhAiEArArXATVSCCg+Qhe78XYH3OcJQ6ZaMNHD7bJzv7zWok0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22084,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdLJ1lCRA9TVsSAnZWagAATRUP/3sBeNberB7gU8qAJy3j\neKp0WaH6GD3JqsP/gS9bUIXyHEdBPFqtPXMwAh4HZ0m8aClWORl2Rfc4tabD\nVpMi/ohlEEChK/RlamKrJvl78jZt6tsW5Hn3M5PodyeHKZTKDbkx2uLu9Ts1\n9n+0oqoofpcLyB9Y97zok3+szCGjJ7rvKevfg7TRrY9Ltu0roP3OHWf4HebZ\nWIGfEeliiud2Abs+QCkSoD3SdDE9VOn7VoOZlHyOY1GSVJRvNAMPyIFCNgrV\nJXPOnIeo8Ty4cbmChylx3K18zFVBmO5ROB0KFPxNajPn60j7ciKri8Joxz2m\nEy/PW8kxoQLTXSV9D472F1KhWLDpQmV0OgtcmPx2AtaXF34c9KNvpUXbNEHP\nFvtt8/f/6RxpuM+9xnXs06N4SX7q/N0/s6Ci+b4CHIcpbx1IjXYYHbt/TkZN\n/0wpZfAUJs8qPklP8vhJwNYdksy8zWQ+2Lo76/XnE6qjCeA2ayFDYO7U8Fxn\n6z/cv3a7e8bbLIgQkjDdBL2h/tjT5iNMbK4eRjpWdQMvkIkSoqbTnhc5ClpP\nmsZJ8HmvMhmVy2e6qwN3PyNjg0kYw7lr4zoP9j9GqUmMoO3J9NdIO/t5+5KJ\n6NYaSNBiwIrMcSPsZsE5r73cqsPwxInqd2fdEhaJ1+MCqWMruItGKlRH97z9\n1LzN\r\n=Ajsv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://www.ampproject.org/docs/fundamentals/amp-cors-requests) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@canary --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://ampbyexample.com` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json (with the addition of `bing-amp.com`). All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://www.ampproject.org/docs/reference/components/amp-form#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// => Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin instead of \n// Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin, AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://ampbyexample-com.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://ampbyexample-com.cdn.ampproject.org\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nX-Powered-By: Express\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"630677e390bf5f63f82f4d2c6a0c53a20c33bc2e","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.15.0/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.5","@ampproject/toolbox-cache-url":"^1.0.0-beta.5","@ampproject/toolbox-cache-list":"^1.0.0-beta.5"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.5_1563204964638_0.4427107126409462","host":"s3://npm-registry-packages"}},"1.0.0-beta.6":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.6","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.6","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"0682d9a30503b9902b58ce8606201cc6502f8e09","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.6.tgz","fileCount":4,"integrity":"sha512-udTmS1p3kVFCK2zUL1svzzBKLTAEMJs0s8ZswdxqCMG2bPMHLPWpPsplnBp3Hw/H4I3mNhzf4+W1maGa6iHhfg==","signatures":[{"sig":"MEYCIQDUG56VObj3tepiMAhrC6A+QpUdKYO2tEQIw/hvSy4ErAIhAK/w3K5gIsQXzzgTpiw7+QbiBPZBkUpjzz55uJnrQ2bo","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":10741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdNwVgCRA9TVsSAnZWagAAs6gP/iNPOQbVtyMUCvs9xTqv\n+awSRhRRIuCc6nvqqFoV9kP3cyoOX6SKRah4El5VVK+Iy1jR/4TnXxs/Sit4\nH7g+IqgRvLYQ5kqJCeIY5xPdyNmdG+8WNBA95STIkI4dKWyELtvKITeyrmNn\nV2k0bZqog0QIAfB6mb5bY09W4IKMkr5TsnijHjjfOZv9kjr0Lg/28yP5w2NZ\nPiwZ71q2kQHlIypf5koI3gPMcHX4DP6f59nx+5fgKXZxm7vsXRNvuiS/68QR\nCGMBEyhsgiSf6tYqTiPxV4jHNIT1GBplEsOBHOyqW6Ah8oTGi3QOp+f6L5dt\niNQmsTtAOppwM5yIUoOIKM+g73ZywynGjLsaJxQKmmRawHYEXJCmxWVMTU4K\nGq+nwZzUfnXfHMk/Z6unSKqgfJdz+PPdkixk6tGbVmx4K1QyiMREepI7TbkY\nxl6sPqbzAbsYaVO8OUH6uTxDTd00brPNESmp9g7n1tQIXiVcU16HkGwpd4BV\nv1gO9e3wXYnfdM4w52l3QE/9wP+xXl2g7DXrIHJWXY7ApHuXTkLQzlQajZUo\n0EgV5stgEYM5rRt8Rf2/pWsokMEWIodKFel4NWx5x3iPolqA/5i8ZssWdvc9\nn6n2jEUxhTwWLpRGagK1yV1GOnsQYWTEPXi1DGrMc9cSc4mkDfRUeDD1f+54\nC5Le\r\n=c4Xe\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://www.ampproject.org/docs/fundamentals/amp-cors-requests) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@canary --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://ampbyexample.com` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json (with the addition of `bing-amp.com`). All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://www.ampproject.org/docs/reference/components/amp-form#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// => Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin instead of \n// Access-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin, AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://ampbyexample-com.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://ampbyexample-com.cdn.ampproject.org\nAccess-Control-Expose-Headers: AMP-Access-Control-Allow-Source-Origin\nAMP-Access-Control-Allow-Source-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nX-Powered-By: Express\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"4c1963ce6f32ce607ce3925653ab38db250e79c3","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"6.9.0","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.6","@ampproject/toolbox-cache-url":"^1.0.0-beta.6","@ampproject/toolbox-cache-list":"^1.0.0-beta.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.6_1563886943903_0.6491246854122377","host":"s3://npm-registry-packages"}},"1.0.0-beta.7":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.7","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.7","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"6f892e9bf4cc5e9541d239d402126a2a9368c4e3","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.7.tgz","fileCount":5,"integrity":"sha512-GvO4BuWqjhDid2CaAi3qw6xLjERhmxpcx9L1Qn33CQos46eLxogQZdGdA1Lt+GPnuivznUFuoV4FCC8BVnHEog==","signatures":[{"sig":"MEUCIQD94xHY0ph+ULtYs/QHiaFTqp/DO9G5Q4Yld0MlWCa2yQIgdX3op/5YWGCBQzdw+6Amd+vnEDwYR1BExe3mj/QP2Ks=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":21495,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdOGJmCRA9TVsSAnZWagAAYRgQAITIa+T0Rmuf/WVWFCz1\nCYul8H0V3cx0Azf8aKV7iYyVocPActP2TD9a3badYaFuEfEV/ThvOVzKuK5o\nKglyXsfu1+UB6k3ijpNrkhyAJGp0B6Cp5cJWvY24voHMrKdOygo/E6r/Bk7d\nGc0TSoTpd9a87brAi63BVwDDLgKazC1XYMd10PbQEjcmojvNdyYn8j1QtMNt\nXJEai1+4uL3PDLfpoimfogn8bB+J9DJ+r3STyz0pgauDsWIzJ/Cw56qD7NKa\nRHYZqpM3XOIVJ8O1w2MKacezKq1qvMyJPMRh0q/3bCEFCVLNCuRt3udjVyHn\nq5lFtO6xaUCvbRx/f7r5IuwGmy6haWAKIvCxjIrdYe3r1k0mDzKslZhOb0Aq\n9IrNxvC//gAOsFLtusufs5LPSW8aru3lTYtD/b7NCFHJ6LKnjYKhhKDHpdWr\n/drwMmdGHn/+cHcrw4Ju0dmUkh0MINg1uMi28Usqx3qS3TqqbXcjc63eiH5r\n+ya5P9Y30gOQN95FtOcmmbzIirHDQ6YT3YrZ3LN2LZK+zh71FTo81bkfuj72\nVWAerJuX4dJF0OoODS9OpkVFjUv+T8VYT76pQ9Y6LQf0jrghIagLN4zjsyU6\nPubrlKbh7CFjP21OruMFJif75Hp4FhMxu1WDF8QOi7WN3jdI7xzK6T5SuTms\n6qBn\r\n=OgEj\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@canary --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json (with the addition of `bing-amp.com`). All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"386bd4636da2dfd92569a6f0c0ede7bd2b49580c","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.0/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.7","@ampproject/toolbox-cache-url":"^1.0.0-beta.7","@ampproject/toolbox-cache-list":"^1.0.0-beta.7"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.7_1563976294332_0.4883432105104779","host":"s3://npm-registry-packages"}},"1.0.0-beta.8":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.8","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.8","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"a93d3cd6bc6681928258a25993619e2a4c6be75b","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.8.tgz","fileCount":5,"integrity":"sha512-6GURlYs3a0S8/zUFMRe9mcdQABAsFxpClNUiaxxUal4mJuK5ncm/P8h3g6PQADe582FJXYdR0SsPlf3cYI2ABg==","signatures":[{"sig":"MEUCICoxA+iKEbErNlDHKxDZyKiwXKWbMaY5QwZoseBUAtL/AiEAh+mZjYFEdnLDhkXcvhmHo6MEFj1zKmJ6XcVcx+32zAo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22373,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdQqwyCRA9TVsSAnZWagAAFysQAJBUvyHNOtJ01qJNjyGH\n2HwbHSZxVoeuxH8H/N0MB/89dYbOEKYfMxo5FdEs1D4ntMr8g+cGehnnA8hk\nNQsDNJn+jCK9RV7la1e4DI2LG34aNBICLBITz/NdnC0VL4vQvidh6I+W1Tc3\nsfCs5VvzHKNX5cVpk5Jui2+7c3fLhQgvu8GGGAgepvUdEonT3E3bqSu7daPZ\nVCuAGYR83Tg3fAdBKG5rWFI5NpHfaJp4E556689mgEfxuBIS3KzmLjJXrF+W\ni/UmpSAPmoniuSYA0qzwIN/zQOSBOoq0mkkGELBQ+/2seHYWlZ04oYa7Apm3\nQl71yXBqsD/aVfT8XGtHgYkn4fH4DD14eEQ9h3iMv0UgPM4CqwCj1PTMEHQr\nr3V3eD1Ennd5ZkttfdACBozTCU4IzsSFFKqJ3Rvg5Ao1PoL9J0GppngEbPq6\nKbqUf4E8Q2d2YXaZtKk3LMnrr+BsiOKqzwN9CTsS5PbbtvvrZpucdyuXuA30\n/muepLrBDTqPzvfkjh3IfGmkAWDokYiz32yPx1+nvcY66J1/rhrzPyjdiaue\nhvybcZBcVJhn1MQqLinYzImUeyW68LyHsUFV98i7jjVOOxGPlCwTbcLs2ric\nqj34UUMy7KHvg9rbVimfWBI6LWX96XwH+D96F+FC0NfT7ChrKnsVfYVRQfDQ\nVzfL\r\n=Ju9h\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@canary --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"6f291b4f9b0a00a24e3af763c918a2b70d47bb5e","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.4/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.8","@ampproject/toolbox-cache-url":"^1.0.0-beta.8","@ampproject/toolbox-cache-list":"^1.0.0-beta.8"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.8_1564650546148_0.022694046098731935","host":"s3://npm-registry-packages"}},"1.0.0-beta.9":{"name":"@ampproject/toolbox-cors","version":"1.0.0-beta.9","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0-beta.9","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"6d7b26ed8f1aaf98b4fd59b072ca63ac40501c86","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0-beta.9.tgz","fileCount":5,"integrity":"sha512-nYr9Zy9X7CTJWh3Y+B0oW4pilCUm6WQaY44YsVurOwhRw5aBbLLmZhVZd6Spoy1F0EGqfZWI2SMjKDGqPQYjbw==","signatures":[{"sig":"MEYCIQD3UIERQGRm82dn6jwDPMBxTwyKZ03SPWI56+cBAT9vtAIhAJeBfjyFIlCsgmaQ2nNtoBufyt/T2dlj8i/E7gURQJvd","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22373,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdQq3QCRA9TVsSAnZWagAAX4YQAJTi5f+QjSWWf70gwFvW\nHCW4scoLdpQfXE/XvFWnLV6Nvkhcw8xnxN2LomjSLKpKluESYhnIbjmx60yD\nuPmYw680MqAzEK2WhJzEAeH7cpWrF6kobIsA9nVb9pt1oUGTPLtdezVs6no7\nWlruLO0yOvgm8pCtsbWEJe9lF3zAZW/Op0ZuFfXKAJ09wq5Mq0D0Zn7z5Xx2\nqNlHosbevNS+hRtONgDFvOXwD2os7EL310WMdI+tcthQL91w9ntNjlkexAVK\nj972UKYb5x9Jlli6xPyRO/qq3ezcNRYGDpYdVOyrnrKgGJKJcAq/MgdnTlSg\n+8zKp4iBxRy6ZcBPiwec1rjYUtrX/lK5I/fgo+8WmvCjvXwaCv+rXEKS6QER\nkkmH1L7fvMRXovqGbiVrYvm1rMMEI9ZGWj7qHkA/h3aSR1dxG3hJlUrecbOc\n45HNVGzjqWwQKKec7B7UTSMSFn0y0Lx2gOQBIXPsER/n8ZSJrfcyBWPDT1Rx\nGDRtV2zahmTj5z4sy2q3CgFAVI9y3PJDtWufJA9OL8vhkmlyF5NYxSo4x/AI\n+3FYpdWNGLAGM+MUo3cDmCEqnLQ6jG3W0gIxwywkFWorHsv8MUy/3IEq+DWB\neXgCBh4arJyZzbXBQxplSmZT4tKtkUlvBRkPSkgZ+eIK8PmMJgPnEMk8oMOu\n68sI\r\n=52j9\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/@ampproject/toolbox-cors.svg)](https://badge.fury.io/js/@ampproject/toolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors@canary --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"2b6eaa91c3654fc1523f7fc2ff93b37579b52869","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.4/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0-beta.9","@ampproject/toolbox-cache-url":"^1.0.0-beta.9","@ampproject/toolbox-cache-list":"^1.0.0-beta.9"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0-beta.9_1564650960289_0.11903573439422388","host":"s3://npm-registry-packages"}},"1.0.0":{"name":"@ampproject/toolbox-cors","version":"1.0.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"a3c909c8fdd98e4d02087331909067530b715598","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.0.tgz","fileCount":5,"integrity":"sha512-foAIWTXl74Cp15F1eVnKNN5MpsvX0vliyFjiLZZPjfZ+lllxTR/Z5SMLpLSmBuzK2+pO8LYlk0nMKmTwLUH1Kw==","signatures":[{"sig":"MEQCIG4C0PhtqFeoYgQo2TE6YeWVNLZtn6WJbVDtwWClLITSAiA9FnWDYccJCH1piaTrGeAXtRZgOczSlUsqUKoayGmndA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22338,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSdwxCRA9TVsSAnZWagAAgDsP/33XYOUkxp7TlA50M+Iv\ngm825Pos5oczUhqBTngZSVx4mFNeBiLKzgc5iwVD98n96D28Wd7QKBkICmcT\nhd02EJ1dRyfsmfWlvUziax7cwyu6HE8pLyJWxUCxmy6a++38tRadPawvNkF1\nkqc4YKZkl5CvrP/f93D0i1fr5/6RmhuLLwhq6y0SQpASU2xCL7s25FjPy0/5\n+zBqQTl4SVlIDj/GljsVnQ4RLF90iKs6Mgfjjwt00uXs8l9pFKQlsf5HrLOW\npxMf+N9fCEPzpfSh0myjJzq442m4GsCIIoWc7wgz0fa4G1yWb9+R+yI9ioJZ\nnlmQtCRR7TKFBdMHvtB7O8m4Swy0nKWmo675Lh5nN4K8SP9i8RgZYMgrlpOg\nYpLBzN/UYWmzjsgbzvkYIzjEXMe7wQN98G4c3lf/wZzmapnxq5mTbvML6aYf\nz9IKyHlt5qfI9s+WUC3fC1FBpYha3ydxjkjWfacrmXdo0IYuhyCOjkCWdmC+\nofE6Xhwp7mgz9yFencgKIcw9SJ5Ci81LfU0y+AZZA6k+XuexwO1P5CSLKWIy\nuHZWUEmbk3rK1cU0N2DX6G35D/UsDIJ1t99wAGl45mdvrIuDSjXot6fN3Kfn\nubLe2JJ5aw5lEN6US3b942yVxVjgNCCtyDwVymzgsQr5aP3Wet8o7XHso6C3\nzIs1\r\n=EmkX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"cc04a8267a51e57290ca81610ac6854de1aea986","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.4/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.0","@ampproject/toolbox-cache-url":"^1.0.0","@ampproject/toolbox-cache-list":"^1.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.0_1565121585081_0.26762610743868365","host":"s3://npm-registry-packages"}},"1.0.1":{"name":"@ampproject/toolbox-cors","version":"1.0.1","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.0.1","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"3b7efef04a4d7b87a6260ce8edd30d94847c3182","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.0.1.tgz","fileCount":5,"integrity":"sha512-35vC/7czgJYZdME63Im9kTLXB2dA5btFadfBBKQnAPJEH/BvXGmzI8CqI4EjhxUZIaK/U5Wb0Xbqar+lAekJ1g==","signatures":[{"sig":"MEYCIQCBO/5ffZxrMdXtGjPZNNyDHIw3XAw1BfyNmqcFX7gi4QIhAJkF6mlUHbdUm43EfmTepmq+TUS4aNlSTieBxmI8t4LX","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22338,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdSd7jCRA9TVsSAnZWagAA5HEQAJ0njG4BS4rPTSnayhOA\nrmNOxmEADsJf0O57Rmoz6zJvf3PxN5+Kwj78AC1vsU9RTmdtmwpm2lAf0+/v\n8I+Dt0/KRNvzlOq9aw2BJJDHdf2NuoBLZYncvuM8ao65c3Uz4S65f1A5utyA\nvRl/KNW3x0N55k1ZSN9D+LSTqydgNRDpqB1NYwsrzkX8R4QRnl5N0AzdcI83\nJwaoG+2OoeW1Uj7DuspOE2VLpQslBpPUyKcb6OsNJRkJrMyBgirCfVbQi6o9\nEHhU4QfWU4Z7ae1/8kuFxFqp4ut1TJ+9/4pDAuPypq1Y48pugILWmn9LLpXd\n3bLuScBtblij7jfBYzn58ENYcGOG8lAjiaYcqWoK4+Oq+xwMtt77OLU8QqFq\nPeSlq5YSGlYbAEOZ/bSL/Vmibs6rPSM8BH5dT/LbsqYXqV5Au4T+fTV/OYWt\nSsxK9iAmGMzQqTvm/0z0myi1weNcDpOpIGNWrBbgPRbagUbCf5bNUwdTQCjL\nxp2FwzLPo90+v8zVlR0cgN9uvsDu/kaxOTzauADyQRXSsTP9vNV3QDHVMFu+\nx2Yc8OSMvkCOvG1nHJS2e+y2K+FCopefaC3yYnri5HgkIImgMW/yawIseiR9\nbpH7L97PMEkwFH4fsFhqcLRycho20Kq5HU9uJofPu1+JC3tGC5+9XeUSsexx\nGfai\r\n=xUuE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"4da05d4a419241bbcc8157553022af3a84676e9a","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.4/node@v10.16.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.0","dependencies":{"@ampproject/toolbox-core":"^1.0.1","@ampproject/toolbox-cache-url":"^1.0.1","@ampproject/toolbox-cache-list":"^1.0.1"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.0.1_1565122274094_0.0951360614026786","host":"s3://npm-registry-packages"}},"1.1.0-beta.0":{"name":"@ampproject/toolbox-cors","version":"1.1.0-beta.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.1.0-beta.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"b087513cfb4b236802e7a406108e07c4fa544752","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.1.0-beta.0.tgz","fileCount":4,"integrity":"sha512-+/WfLab3zd6LMfnm1pfWc+RegMfHqxq4C7mNRcnPd9c5kmz5VjUjXpNEaDLAGDUjihrANWNNjEE08uiszZ4z0w==","signatures":[{"sig":"MEUCIF0lpCBG5hl+/VumHqBLOuVyyjCLq0AHv5Afgeq6wx+fAiEAmyb9l1JKdOdtMO+bT3WWSWWI9RPk7tszRZpHgYM1xfk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":11031,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdaDVDCRA9TVsSAnZWagAAaYwP/AulG8GD/0X/TKwqmWoY\ngFXfFli5rPava02eNErQVe31hwHkWFOoP/UsQy5XX1MBIA69lKidzPTqIwqj\nzY45LJxaLo+3ZG0fXMSCoY2n9uSrgVC+slpEGvXAu/LMIwbvBEWQ5sz/i1pX\n8puqpwR9uXqkZKrJMMz0rUubX8hDWyr0hsUVOqwsd3Q4Uhe1MFdvvWDFt4tE\npWEHH0p2muGRFHUccH/SiIgUrrc/h34qSHea9U6s1SDzR25Cmmfg8W4k7fPU\nZWXvtE6yEtJGA9yCxv5FbBCfyv5ZzsUbG5jqRAnUFJk7P8AqFjscqJ0B8GDj\nEoqV7Ffd+vrmD9/6DYIIlkPexyVdV9QcsKWczBmFeTgthomZdKjUl3vWZDG8\niE+qBTtnRpGLyXmRXN9ORXZyQdjeaWzOLSYXsE0plOYimYCE4Ek0sr72KhTm\n8i9/ZG8RQ0MJ5J9joUdzJl311b3vFETNd+zre3pNM4Xctzithze6o0RUbdF/\njRkpxbLEtEWQOjb3zLjLu+cgQgSwCyhhlUigIf0uz9raCSx4xcFw0YeTSr5Q\nUIF1sq0lsLpjpQwnJCytN5nplKPkf5cnwNzbixEpA5mqf6tx2HF3nfz4x2RS\nDIuGq9dn0ZjMUI3pN7KHWp5ZxSw563j3luJMYcyN18AsqS9KMPY3Qu+0cTox\nmYOO\r\n=QAwv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"cc04a8267a51e57290ca81610ac6854de1aea986","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"6.11.2","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.3","dependencies":{"@ampproject/toolbox-core":"^1.1.0-beta.0","@ampproject/toolbox-cache-url":"^1.1.0-beta.0","@ampproject/toolbox-cache-list":"^1.1.0-beta.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.1.0-beta.0_1567110467059_0.35910834722033025","host":"s3://npm-registry-packages"}},"1.1.0-beta.1":{"name":"@ampproject/toolbox-cors","version":"1.1.0-beta.1","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.1.0-beta.1","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"6c53c4fa2ac9bea2e6b5d75f1f63699442aaa953","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.1.0-beta.1.tgz","fileCount":5,"integrity":"sha512-tlxJS1BaqDXndWpyv/MrDsEF5Paj03Re3guRbk79pJsp3ccJoVrRIYERsi55xlfLEU8lgfaF0TsHoW4W1F+zuA==","signatures":[{"sig":"MEQCIDm7d4hCnfVcrVByEXpjgcz9Qqc0Xrl7lUL7RvU7JKkIAiBIqdX7mYY3LuA/DBNwQM3kLKbT7agKPMjCZSIT/ulAtw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22336,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdg9ULCRA9TVsSAnZWagAAp+IQAJAKsDh7hKSFHab152mj\n4ZOz5ndvum0GLt2cB7GEj+nk4yCRhiEKltDQSgOy+LvDbmUYfLGky4mPr51l\nTyavbIKNXqtEU3MyqSqHZdQ9SYKp6aHXLrquVnArg1QphtebyQSwO2c+Eanb\nDm6IvDawGvPGyXKnVnOl1XabodXLJ/Jc7/zxtaEsUHZYPH522HPkjEcRbgl2\nOh+V9fPDrDfretMv3IZa9CoXKkq15EM6Rk1UuOFfhWyVTsE/GvzyOwgHv41Z\nD2Btv0lajtNLCddvd/Ubkx5qiNs/E41n07ejVO8XSvV5naTAWgE2c3qDaMiS\noalG9pOVj6jHELFM/vrS9Y4BIsipchvUY4MLp9suIAL6PZop9MnQ/MTZIC3P\n/f/FMHm9XwiaZxvT2lPo8p6diS+GNAg92S5huRFyYJ1QZzbvnd7QFWVPDjTV\nxQztwYb4jQ6rp/6cBbvuqarZUcukFNWFnksluK1wap0MLixvGvOv6tCtyp/J\nQOt/Q7QKiGFB2WvHYfDOlBkDvYzGOARlVw+cg+4R0VrOvizmZbI6qVmM14uZ\nJcIpCuR4A7W8YhRcqNCuRbmFF2TQZnAbI/gGwd0tWz5+rAz7/GO7ozl+cfPN\nGh/bAkq52nd+Y7O5QDhQ2PcsMJ9koadE8O9/HI3oZnsCItim2dkAWJhJjd5D\nRwX9\r\n=nBB+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"b5c4db9bdc2962da78862a181d409f6082b9b3ce","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.4/node@v10.16.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.3","dependencies":{"@ampproject/toolbox-core":"^1.1.0-beta.1","@ampproject/toolbox-cache-url":"^1.1.0-beta.1","@ampproject/toolbox-cache-list":"^1.1.0-beta.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.1.0-beta.1_1568920842624_0.4768703912529779","host":"s3://npm-registry-packages"}},"1.1.0":{"name":"@ampproject/toolbox-cors","version":"1.1.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.1.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"f2e3fadb5e24f5702cdea14f348e08f08b506b9f","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.1.0.tgz","fileCount":5,"integrity":"sha512-S4SIEeY2cNJs0/bT2kohp18HaidlyBcphthLHEIyWVURV1uxyfSid7A5ydE7Rh6IQg01NjPeKJWhtdrHf7PDRA==","signatures":[{"sig":"MEUCIASks4C290T0RuZOimfpsi3MuiVasXPNuZhWeiw3dhzLAiEAuOmn/hG/UCkgipjuJVzRx0Z91Xs+jSMQvJv47TvW8gE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22308,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdnJm7CRA9TVsSAnZWagAA/sUQAI/ZGA7xe6zSMUIpV37B\nYaj1JfsoSZGQkuXpjw9iRI4dk+GFgD5w/l0wmtUJ6+xkR5zdEz/GrHlfvb8b\nKGExEPWW8P4+1LK4WJyWStoVVs+3IctXhxD3Qq43On4ieF+jI7bdDRu9sQRG\neRXVImgRE6fq3CeTma4VYtWupN5+/LP4aQrttghLBfMaunl29YE64H4LGp2C\nlf/SoaLVLv7tmPfQ1sInMFNA8+4NjbuOwNgnHDavEg5vq/8SIvomhbq3V4SD\nnX9xOn3XiZ0O1v4uXJxKj0Ov+7JxscE5iXzUTJ9VjrmGQynW18QVSpkukvES\nhUEYB+k9DUc3SXxIxzh2F1r77l6k90Tv6Bskivnng0pFX6pCQluAzA1fRzyd\nRPDn8mXYCgrDUfm/OLpOvAuBiLLF+7Fl/nPvkpACp0Ce/sTRxEj+nzohD7no\nMcdhCQuo+ocg4js/4a5TtniQo1Aqtgjq3FERUfwLCIKg6Wjt4nSzhUTaoPky\npdyUASDw9uhHNvuYywclp4TTs6AU5padaerpaa71lmfVkVZJ+FAYl42wpxFj\nhiOBsQjkfciS/iBK4112RrPkfhNQaVAmWaWO+Tor6Do0vUI67LL/PpFWbKIE\nME4oSNkP8FBDfw1kM/L9QUaX2MCrMqG2nx6fb6uLdKaWceWR8QVuIG8wqchB\nbJqs\r\n=zu4Z\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"783938063dde0c32f5a79af4148eec53f26e903f","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.5/node@v10.16.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.3","dependencies":{"@ampproject/toolbox-core":"^1.1.0","@ampproject/toolbox-cache-url":"^1.1.0","@ampproject/toolbox-cache-list":"^1.1.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.1.0_1570544058511_0.6118837342675885","host":"s3://npm-registry-packages"}},"1.1.1":{"name":"@ampproject/toolbox-cors","version":"1.1.1","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@1.1.1","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"prateekbh","email":"prateek89born@gmail.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"e6bc60388e157f57f55a28a61990da205c0a1584","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-1.1.1.tgz","fileCount":5,"integrity":"sha512-ABaVF0aHkizQVLV9sxo99lpCo2Cf8rjsbb0w063D3s/GJ/YlIVMnAmShkUC1WheR4YJA/1xZUaFoNKJXJtJfZQ==","signatures":[{"sig":"MEUCIQCOtm+NlQKEmiZiDdwWd/rTSa23b4dRPBby2HBOquPAkQIga0eH/rntCyilc6Ez3Y8+3QJ65mI+KtX+Q2zq+QNTTdE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22308,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdnKCMCRA9TVsSAnZWagAALWUP/ip3+pJ8/rn/myGrkciG\n+JQpzzqSXdNH1Mmh2py1V/OemovqN4sNaYnyAtSngbgDC0tabOf+EL1yaQaZ\ndxJ64a+ElcL0fWotVrCwkPe8dprWc1G2/ElQex7tyzJzOT5UlZbUyInzQfAB\n8iUmn6Z7lctCbOyI+rjWhxwAdGpPxwKbln2RsVzfr9xOZcKlG742ZNdTsL7/\n2COIMW0RsAtkmA2YNm0iM8J7AuxXE0vsiPG/ew+Wk1q4m067LIX2rDHXKdyC\ns9Kv1eiTrQ0R6Y9DAg3X54f69e4U47cBwD6qDe68TdD1YxRBvc1RCcYVjPHr\n6bl4HmZUEl3zP2EVkGviY4VqBZ1fSE09mqA6l2ldxz+O6AMEszMKhOlQU3Qr\nzqhO8S5uSyI4/Nuc9WzCIc7dcWR1XB94ubKSZDKxXkPKfUlkBSadQfeEF4h8\nps/ayM8m69aBOTcxf4gFG6CBvv3TJskB/geaFcx4v7CusiuE3P0bCCtFDnT5\nVUMpamMKFh0XitYf/83jXhNE6Dl2YYfSCrF7YqqKVJ4NqceRyZe/3QRL/yfq\nHhrhK/H09QoDCPQ+l9+pADvkThD6e2Zk3LGVfR//rHHPRfuEcSsJZ2mLrQkx\nZycDLSOoIgY5NtlIEQRE+lwRWDV/2+dJvfNKssfz8aFRyoGElS0quJ66LdOT\nppLg\r\n=s17N\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"6ce20613dba3e66b7722df599f62f35dc6391962","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git"},"_npmVersion":"lerna/3.16.5/node@v10.16.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"10.16.3","dependencies":{"@ampproject/toolbox-core":"^1.1.1","@ampproject/toolbox-cache-url":"^1.1.1","@ampproject/toolbox-cache-list":"^1.1.1"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_1.1.1_1570545804071_0.7766087570742186","host":"s3://npm-registry-packages"}},"2.0.0-alpha.0":{"name":"@ampproject/toolbox-cors","version":"2.0.0-alpha.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.0.0-alpha.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"sepandparhami","email":"sparhami@google.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"88bee393c1bd4c37d785f3eb09274d47f2e0bcfd","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.0.0-alpha.0.tgz","fileCount":5,"integrity":"sha512-UqmVmxDiR+s2iT0wDV7+UlggfTxQGX51hvEP50qd1Vk3k/PhsFXJ7absXJyGy2trk3PZyZlUoxddYotRnJ9FgQ==","signatures":[{"sig":"MEYCIQDmTOXDikMlB0QGbWIEmK+0xqx5xCk1V8ld50Ol7GJ68QIhAMML1W3kWPDG59ruokh8u2m0aJDrX16A/hRIjCXls0YH","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22460,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeKFyFCRA9TVsSAnZWagAAcBwQAJ7MXY5TWF0V69RxicMN\n7iPsmy+FOW1OQkP6gHLO5ALDJ9t1CVxReLuADol6n3Gn714BuWiQPujhOSDc\n3xvfze4B9Ik9ghXgnaIO3UCEu3wcBK6O+SnZoU6TXwWTVIPxg1jqe1dF93Uc\nFPJlaUXC+1UnD7GNPqJex3WzxNiMnBhzOGgxNGrAJFywYzmGhne2c0Pr7W6N\nbaYcaBktCudBe/+oL9M9z+2SXHay/aGu48QnEnE0F7RH72HHOkN5PeWst+mK\nQuE3YOcUDSmumM1iSOyBEXStKMMcytD4u9NJLaUdd5PmdLS0o0F0DQX9vttb\neJVFxGiaJM5+G3iC4gRwUcLZnV+qLAouodHw7+IPIMn+EDAqtqDkaUm/epy9\nBcesOQDwGDUeSzrHxLxBzUoEUvjBb7Xthf7SZLYGUE2Oe/7qCMaB5eH8NqLN\n4tVk1cXfNJXiP4h2FvM48u3tgYiL+6wwyv1wsfCUaR/3FbhXt7/cy0k/mRZK\nWThZsvZugg6XRnfePoEQyZEUtQUZE3qRDGsvM1JS0wzZMXlMnIRQkOyhuDL/\n2ZFaccas2tEgVoJ6KjlTJojQaD1mboBpq4b0WbX7pbP3ED3un0+QM20gtU1S\nyg6l6+k32yB0c16iyixg8XyCIwMoUnGb40cDvORtx0vA9+PupUIZqsrtHgKF\n88+Y\r\n=jakI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"6140009b75eaa18afeaccf0a5f1996f490dcebfb","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v12.14.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.14.1","dependencies":{"@ampproject/toolbox-core":"^2.0.0-alpha.0","@ampproject/toolbox-cache-url":"^2.0.0-alpha.0","@ampproject/toolbox-cache-list":"^2.0.0-alpha.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.0.0-alpha.0_1579703428898_0.7953443365539972","host":"s3://npm-registry-packages"}},"2.0.0-alpha.4":{"name":"@ampproject/toolbox-cors","version":"2.0.0-alpha.4","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.0.0-alpha.4","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"660ba4394be5a51c2d223e8f2aa07fd2cd582040","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.0.0-alpha.4.tgz","fileCount":5,"integrity":"sha512-/NBzdoPpbrpLmm2sKNS/bDctOJ3tVG6MlxHIvE24ABBcZ10h4OeJ/7z+DaM+yPYV8vPh8k326Tz6tK3VQjk2hw==","signatures":[{"sig":"MEUCIQDS8xzqOa64OtTzUICtsP8J+rl3y1JUP3bw6SNlY/5tEAIgW5xj/Mx+tDp/2KSA4ys2eNY3eRW4NhNl5dOmNaEjKf8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22460,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeMFKPCRA9TVsSAnZWagAA9PsP/jz6Axe0KqhI8Gte2f/T\nNUhedTBtjrV0C1gvVEB9UcthRQADuwVaOzBg9wBH7EQ0NZRddKtIaHrwbZjQ\nfsCEYfGMZ++gc1xfUAcegxYx9+YuCTsxex+5vHDOGmZgtunrP+kUSySgIO0Q\nVNoN65EaS1/hopcfDv59+TOV/9qAHe20mO11EEz5GEzaDs8H/hPBoxLo2uTa\nwhoLakMcfG+UsxP+HbC/S6ZdWZaq3bPZwuIQmGBVeFMxS+LRuckXJt1actSM\nfsCr8p48XEr2v26aOqQ1SRrIBWwIOezBcg/fQOMsXMlHj7papa/xe6UP2fS3\n35oo1IRZKCXHp15aWVOsy1fuCiGZDt7oSRsaWuJWUX4bYL2NCsFFm242QHt6\nTkhNG+N5j/ICHbAWsRVvJq9ZXh30FKOjFaU5VAZ9GPlXEC8vB4KqIeeW5d4G\ngOvHTYbX1PPhI7VmdfsXfEbqsyWv4qnBCw7nnJ+yHMLm/ahRwwjCXRMItSwp\npdWUy8kIPESRJQCKjS2IgltUEQpOWXc4j4qOf4OitEodILubnu6jNbCg3j1e\nZv9CIS6rWAre7Fw/QGvHBfh2uTWRkl7Vm4D4GMaaPD7cNTaIKXnjbEI8TF2R\nrfajHiHlMViaP0UHn/ZpE+MQWCLhhiNIAg0zsNmFzJdtoVcL1tFFH51HarY8\nhCnb\r\n=qmGI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"fe0d72e23b0d537c91fa78c465ca1ea99d3487ab","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v12.14.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.14.1","dependencies":{"@ampproject/toolbox-core":"^2.0.0-alpha.4","@ampproject/toolbox-cache-url":"^2.0.0-alpha.0","@ampproject/toolbox-cache-list":"^2.0.0-alpha.4"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.0.0-alpha.4_1580225166555_0.6869618576679326","host":"s3://npm-registry-packages"}},"2.0.0":{"name":"@ampproject/toolbox-cors","version":"2.0.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.0.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"cbf2a98d33560541cbb1600dbfe9571b79b51718","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.0.0.tgz","fileCount":5,"integrity":"sha512-SWCHfJK9dDTyyaVOvBfzEC1No0e/PiVJCIjTBD2u1+xACgUhNTM9rbXygG67hoJCPM8kpuVs8M72rT0GTzX1ug==","signatures":[{"sig":"MEUCIQC1XzcSPIH6vqhia8QsL/ugzQVEZ232PXpCrlyDpECf7QIgF3Bpy0eaGANvUPPdBg5A0URLU7Rf5OBBtmZXeN76IUg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22428,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeRb6eCRA9TVsSAnZWagAA1egP/0bQhiryYDwvblLunnVh\nTYTQabOnOqyhLjMrQXvNtpIHyrZ9FvGdq+mlrbevKEwHhhJERuysXxzzTvro\ncWrObapcThat/odbE9VvYOU81yWE8R11bKzWd6UxAH8cIIzn8hXSuIBWoCRW\nn4zCVYbIFycMtfdv0gdm22fA+7fMaq+Lh3mYL5kYCMNslcMFjeXtEGeF6UW8\nLS02wGeQ7OfbJzV7oIPPHP+x4oZUGcfPil715RuZkdui+Iz2O3udWianQiRO\n02r5fuixCtk/DvwtY1aGtxqaWf0Qw1y1PfWvB808RzjUozQ0cdFBDcHOpFNH\nydwGrSq/Km4Rsumn4hFF3+1ZdTCxzMB5dwYCnYGgMVr3MmCy+XO45LIOnlcs\nZe6wJbEKFNWJ1uYhF6io2XkS/WBLw8yJen1Rtp8UNGGU/ZGigcpm7s2lf8+x\n75nj42bahHFQzixqOQiNkhiuALK6seALkGUKdMTkp9GdcoQXmD6A1JfKV0SE\nnF9DeXTWgYGJ9w62YqeafGvniyPk2Oik+hKVhaO0tJCvgv2k/xKLzEEjb+Nc\nkGrCfS/9Zx4I5H9O8WHaCLvmMEodtfG761hQmvKANd3hjAywdHvAowzCkLIf\nSC3EhQ6zmLu5CyVr9D8V6zKWYO9rkKe+VeV7CyemLw+iQkUrrOy+0rVh1bOL\ngejA\r\n=PpjF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"908b78b9d007d18d97c50b5a79421d5936150233","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v12.14.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.14.1","dependencies":{"@ampproject/toolbox-core":"^2.0.0","@ampproject/toolbox-cache-url":"^2.0.0","@ampproject/toolbox-cache-list":"^2.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.0.0_1581629086578_0.5480677492588479","host":"s3://npm-registry-packages"}},"2.1.0":{"name":"@ampproject/toolbox-cors","version":"2.1.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.1.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"cea4461ae744f3afb1fb1861d00382d5790f2ec3","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.1.0.tgz","fileCount":5,"integrity":"sha512-fiQmkMObqZB8boPASRDEUUAzbHYIu5OKwI6e/pHYTgs2Nb+wi3j5s4DWS6c6Eyftps7KximRCbZpkY1MEXfdeQ==","signatures":[{"sig":"MEUCIQDtJp4+HRc0XV+7Ygs5kn2dCmGjljUoPXLPGPrVw7WT4AIgXRBq9O19G2GZFeNlvdrrq8P5sWXpusBblcXg5RJtngI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22439,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJehFgKCRA9TVsSAnZWagAAj1QP/1WLDS8jPVRSLwhgBwI1\nayRIGv9sqxkluZwnjDi6EE5zzQ+zRDztsaVNkDbxVykZRLf5pNGkGrMTzvjJ\nCm+zLT3tht88BoTzVMIJjjJzo0p3UQ3t6GXK822q9A1soz/V8ZjWUC1l6m6+\nmZQ3XKbmyOMEoHbiekG6iN0Tf8qzhHRya+1RXqFD2ui8DeRpJN54zln1+kYe\n06p/7eldBe2ppuD5ueK4YVqdcoJl0vSvidlGyI/Oth68rLD6gse10busCW03\nqSAKmZu9aps8EYLshFkW/08THPfoKyd9qxx8MnH6AqExXuEMxSPeKSJvrgtL\nKm2klfgSW9aJ/TNYpGtedvkj2nAw8FVrQvo8qE/dZkkmiwqLlihRJNGVkhAM\n0uFFohTgPQqEj+56wOuqOEnHnLpD7+f/JkJLbyMncuHUFpeVnQTvKQOMtKh3\nonw/u2iOiA0trCxlcKI1bYlDif9JkuHMe0mD9PcG4C2fPTHQ5Q3j/bQoR2MF\nF22PBH0ORrf7UwBdXfWNePrWz7h91QPMtcj2jLYMmH34YFMi2nhL/YFRbMah\nud2MxqH777SSUVVonRkO9BN+89SjKzYuMxXJ5K8nYjcmodh04La0RCeypqBF\n66jYu43aXan9ohKZKCNBClPO787W/GTmjuLZMA4xw3sTRW9DBfN1lqtU0gqK\nvVsM\r\n=csoC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"a6bc962a0af397c2fc21de1e8a730257947d8fb6","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v12.14.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.14.1","dependencies":{"@ampproject/toolbox-core":"^2.1.0","@ampproject/toolbox-cache-url":"^2.1.0","@ampproject/toolbox-cache-list":"^2.1.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.1.0_1585731594307_0.9523960476595525","host":"s3://npm-registry-packages"}},"2.2.0":{"name":"@ampproject/toolbox-cors","version":"2.2.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.2.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"7e66edf04240e4e3942d9059680c24707580db55","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.2.0.tgz","fileCount":5,"integrity":"sha512-K46qTm3/f+8GqK3HBJD/TLOlrUa8e2UonCcR/+JOx37wUrWyDXm/IkuvRIp+lFCR/oXD5SAv893WkhUMH3WfcA==","signatures":[{"sig":"MEUCIEvclKie+hHMXUXm67wvrNVPjpE/OqGDkNLU7Ka1nrBxAiEAjGdzRu9RyfkkHhVKS+KdvLRrCEJzTFl7c2nvAUiSpgY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22439,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJehvKPCRA9TVsSAnZWagAAkkMQAJWgeWw2sUBQwvmgPOTe\nTTPCjcFEj6qMRGj8l7JsEfegGSvMqoEnnp6lw2OvocyBSgWe7jucaazJnjHm\nN41owdpJsZ/PbyVqcUtU4yM9vWJWlMqULYUewnNMu2xdhRaDHgaj2UOAo2OA\n3+NbElwvG1sGRBXn0doEcK9jncAIJtBmo2bntOS9/XoFc4coC1FJld+VpPUj\ngCdjgqIuLePyqB1IiALwMD5+ek2iCaN0VbYh9PaXTdQS5ENGZyG/8rsfLAIF\nXWl01AOQzIplAtJ6hSMk9DjuDd1qaK4DpG6zxs1vieAByRzRLr7CZzTyPpfc\nrqO9c6J2pLZCX7OLCo6DnBVEoZz7zSxkJu0h/4T7u1Hdm6K7dwBdAeKWyvAC\nl3xW3GU+NxbY27oTbT2b96GU10WrHzhuuGxVEkl3GaPFHDj9FJDNJgag/v/y\neiNEkDjWHRG2Gc35lY1/A7SFUlSYmBVRhuisZNAccDpxdk5PVaQKg86GOu97\nZWwogihJW2AYo4Vk2FjCs4EqRiAuLflW3JgbVmYfcu8b/mQzryL7IQsuE3rw\nAy+F5TnSPR2oEbRHPJ89LPZptV6MHtoyr71N8wLwkp0+HD8rEtjT3WhHT8x0\neXv/ohGt8Vn4XKTqnTbNLG829pjdHDto0UEeLAQmR63Zp7r3nSyAV/uF/Iuv\njTjt\r\n=lGWW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"e2bea7ac7d4cb6a57d196e124ee8a5f818123a02","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v12.14.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.14.1","dependencies":{"@ampproject/toolbox-core":"^2.2.0","@ampproject/toolbox-cache-url":"^2.2.0","@ampproject/toolbox-cache-list":"^2.2.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.2.0_1585902223292_0.24093674858396485","host":"s3://npm-registry-packages"}},"2.3.0":{"name":"@ampproject/toolbox-cors","version":"2.3.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.3.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"766767a6cd1ac0706399b1d028db46693e4af841","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.3.0.tgz","fileCount":5,"integrity":"sha512-+b+g5JbXcrVIaJtk/xpGW/kSx+RrPT2VMx/o6r7ZejVUg+XppaYuL+ipC9lNnB0oXdjrxuK5Hd9VizYA6w6jwA==","signatures":[{"sig":"MEQCIBPcftNrbAtdLG27fPdLV55b50UeD/lr+NTiD+weQf7HAiBDU52t8nn8Z6ZXSpSsa8pUo0gsBlNdfx0yIPrhIY6Swg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22454,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJeltSBCRA9TVsSAnZWagAARyMP/RsaRmc4yO5ndIEIJuDL\nvCIga72Xichm2NkOjIQOtttbA/VLzlMeXfzqYMz1n8aTiegXZI0ACQt9qiAY\nZXFV/qQ+tYcyrkwy/AoFk/7AJMsOfY2pJ415iHg4WAYuJZFD/E71dytYuLlq\nMxliwtvD+acryN7gNwmjO2PJh/fOOBQnd/er8MnmacEL8F2LUYCmp00U+LQw\nETUTolDGMREK745zm2d0l002o/2N2YSQAYGPJ8gpfpn/071/TbVJWLtZhQLj\nVG7CpLG2lF5j0oMqZ967KhgfympfO6aaOzhgAxbtZ5AQwJwTBMfqSd11HR/4\nC8q86VkgMuFVZiaJuRF+1UDGXjE2dtooDoYDX8Alk4LEMK5IECcGOirtCoDT\n0AIVts61VBtrryCCkOujYq8+LmaHYozS7p++voeBMHb9EJKz7mQwfjUMQb+N\nfIfe7wmkWnS/odoEQbeUl8fpu13M43EDW5wf64eA2/OQWz7cR3dmWKbNdxug\nTtGE+XQxmQXCypubwOCCZVYJzJBxn97RR8Ga2BC9nxuDZ6jMQGOQ6uOLX/Mm\nf/8wgDlxG4FD2dxXSZHV3184xyu5SaSo3CHbSmmGRNq/8d1SNw++2uaT1iKO\nDJH4Hv6qhp72lJLmNib6QOEpns3b0hiXyEt+v5MwyLJkEghc6TsoGn9yBH+J\nHbYX\r\n=Tcw+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"bb7eaa6c720044e84f01c6406f5f0805dc637923","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v13.12.0+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"13.12.0","dependencies":{"@ampproject/toolbox-core":"^2.3.0","@ampproject/toolbox-cache-url":"^2.3.0","@ampproject/toolbox-cache-list":"^2.3.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.3.0_1586943104535_0.8713007047219423","host":"s3://npm-registry-packages"}},"2.4.0-alpha.0":{"name":"@ampproject/toolbox-cors","version":"2.4.0-alpha.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.4.0-alpha.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"0dc16ee78bf500429c14c85abcbfea60b5e56a9d","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.4.0-alpha.0.tgz","fileCount":5,"integrity":"sha512-JWXXgP9j1iN+P4HeDR4A3DMa/dHu+2FzqYhOL3btNJzKryTvCcxBYI8158yAEy1G+zdvNTPMakbOBBHl50zl3Q==","signatures":[{"sig":"MEQCIChsMTJ5T/qGo27wHqbuMy1vZ1uowkNXLqkre3IhPKYkAiALj75yHIaKBwyRj/Uei0V2KUdG7Q24Fg7MHC8Diriwkg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22478,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJesxTgCRA9TVsSAnZWagAAuFsP/jhW0R61VCY/2HgH5GHA\nT34nbE7RXFHsE9UDW/ixJN1TVCuDPLuBd8AZmXICPB6/BrVL09uoQLp3faTZ\nv9awl9KKTQa1NvqlysQKInXtaHi6+nzC9seV8ClmZMucIjBfk04Ne7DZT0t/\nu4AeQzxhWZUJ79RdjdoSTl9+e+nVMVJchpgTpv6NiXKC/m3oV358IS0wEK/y\ntOvPyEpNfsqQrFO9bLpJDG3ymL3IfckzBaDbRrhUs7HQR8icBo/v8byRJYA0\nLgVE4qJCariwX8oRC6Cxbmc4qq9knkhyxyfN+e6n1rTusEQEuyffeZx5XsLT\nH5dvxWYSD3cYY+zD+fXmbNza147ANcPRwSN91t30cCdYEEhyLgEm47nPhl+p\nC0aMkxrcnYN3mcFNhZFOBxvB4u03d9UeeR4Ejeg33qFyOFsxdCd/lBFZqlPY\nkEAkCzdR7eCA/zn7V5GS+Q085W9P6T3DHC8g/1gaXVpV06Q0a0KMqvsLYSXx\nCoIXiV7hBWLEo1sWLwij7/9DyjNq8GEWAjnHpM441IHxWKpDiFtg2aUZPlrg\nJQiHaKd1yByNbvjD7qaxjZxgVH7CLHUHXUpxsWw7rvDE6OVDoVuJKspqTzNO\n2X9d1J6nBiEiWsvq7vaWa73mmXecjkbKAR7LPPzyWNQmDPxYmo89CX83AS25\nBQdM\r\n=CVfD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"aeceb5cb83cc111c08297415ab469696f2f7994e","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v12.16.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.16.1","dependencies":{"@ampproject/toolbox-core":"^2.4.0-alpha.0","@ampproject/toolbox-cache-url":"^2.3.0","@ampproject/toolbox-cache-list":"^2.4.0-alpha.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.4.0-alpha.0_1588794592163_0.46021997869148956","host":"s3://npm-registry-packages"}},"2.4.0-alpha.1":{"name":"@ampproject/toolbox-cors","version":"2.4.0-alpha.1","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.4.0-alpha.1","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"01e6d40f0362c9b5c7979876e8a441d1ccbbc990","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.4.0-alpha.1.tgz","fileCount":5,"integrity":"sha512-SLy9Dsz7dT+Xq72+VxiZjIlzeuV9t1WrO5GfY2KAjN1fyh+7xXhzcQQPDNrheMXTAfyr5eZQ+vj8O6LhoMDLCw==","signatures":[{"sig":"MEQCIGgnagMns/sLAgfNB+msRlMFRU0QjHxbRrr07/BVrKAGAiAW1nMo+WJkeI0HKX9T6RSPWOOZprUzmF9rasJSCoIA2g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22478,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJes+wXCRA9TVsSAnZWagAAU/4P/1viL/OuQ2PrINvY+TZa\n8tHiNnkdASjSfOFUAKbixamAptsHEc/v3RlStWM4qaJuZBJFQcTwv8oX8704\n5H9WKlYalQhPkpHMiJLo5Ji2SVNAbfLzbhA5YUNpayysDD0y+rbkWgOyP6Jj\nh153NdacdlDs3VikyGGtzJonqij0eagZL1+QsAX5hOt/QBqoGiSTg2VzEJWC\n84919WH0veRBTWy+qo0g3aUX+xP5AL79o5R8T+yCztYHprrcJNOogcApCY1L\nCFCMQ2RPiltIT1OCTv6qMRAMSZm07QVPFjdnoA5n2YXIxUeWFRbfauNH9Rru\nuXjRoCxWwz1wga6VHeSIUEFCCv1lgBcgw9YLO4iLAPqNl0L08t/FVv6yuPTa\nKnLKx4SznP7mOHVQsJ2RXGzRbtm5qks7ePLpbbdiD4qOEL71/USVA50im9E4\njTcuORefR1JOnJx/Y7A+hVx1sfd8AMEd7w9xiG+CVgfQ7Xz3uWE3YJN2n04+\n7pAJEt8Ixp7aG7cTMWxbjP7+0kPvJVG5Yca+tnEV5hPAx8JWoBINEQ6TdVtW\nFlXbgxlEoC5DEL7SqZJna6ILJDt51tW6wVMpVWNxsbMILRouSE+oBPLrNPNg\n+a152/eDpZu1XC53MptmZhbWPIv8NVKlntjWR0P9Iq8QY4SUAKRM+ZvqswOa\nFD4b\r\n=AT6T\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"64a25a757ff6d2acc9a7d59ec718a025c713b63e","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.20.2/node@v12.16.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.16.1","dependencies":{"@ampproject/toolbox-core":"^2.4.0-alpha.1","@ampproject/toolbox-cache-url":"^2.3.0","@ampproject/toolbox-cache-list":"^2.4.0-alpha.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.4.0-alpha.1_1588849686671_0.32226554457109313","host":"s3://npm-registry-packages"}},"2.5.0":{"name":"@ampproject/toolbox-cors","version":"2.5.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.5.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"8e72e4cddf587aa9d8fc7c0319458c80164a9da7","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.5.0.tgz","fileCount":5,"integrity":"sha512-xOJlIQkQCa/73Td5Hzpd88tI/5Wayn5wiiElHLb5DdjtNcnu03OrKiZPg2upoN27XCu3oj0HmafoO+zZ4Qtkkg==","signatures":[{"sig":"MEUCIFcG4Vl7ndg65mCgnBmo/Yjz7sIz+sujuWKLm0TpCWwEAiEA6lrOf9ViJLQUFwneJVZYKmleP0PBFo8l61xxceN06R8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22454,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe0PaOCRA9TVsSAnZWagAAvNMQAJY909KuaP5g9wHorBWp\nGLU0sGDJP3uiJShd2zHR0oOkcQO3o3QtonJFVn+t7jKukMk/t//ZswkSjxCx\n5eQJrUgRkTGnWcBgTzX+mdO8cLXLDCP0Dln6gkdLPoAy7536gmqhOTXHFWC4\nhQb9UrxaNNFRx3rKa2UOCd8xfcSHEVEQwDk38AWNm1qOB4xwOnwdWgt1gk+0\nCMc8CU2B1ptgaP/KaBreUI8NdqX4Yp7UmdV2hljct04rfRO4E2Kfkj8M8X2K\nb4N175x4wy8eLyCC/FGMgi/xpxvnLCW9Dx9LmKB4oBe9tuAaY2D4Iob38HRN\n4+xsqwG8vEUyh9Hu+oMaIRMyA1XY78PLYcm6/6vy9oDhNOt/nGtQqhENZqxf\nrnc3Y29h0K4r//pYknSsvGbswC782kzJRT4uOW5hJvgpZe12M6vGxVXtDUoH\nHbc9EcPijnHUUEeQ/hPc8PTs5G4iTGJTOByNlKtASclJhy7FzBGO8SEM6SWk\nmpSzUJYIwEgrb9isfMAhlg5xi1cZdj69EKOBGOxagp0hUyX44LROVn/xkL4K\nyGzqsRufVtvVWnbOU3izsQWXa8VfFiGcTjYxwfwPb1eLm3bjZLIXP4dxpF4C\nprLk2JE8czGVfnokcLPzxTSJTryknqbgosnutL+vylP537NpPgkMCY9ku7gp\naXll\r\n=076e\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"c26612cc3d7408fdc1451bcc8e0fecd67ac9661d","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.0/node@v12.16.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.16.1","dependencies":{"@ampproject/toolbox-core":"^2.5.0","@ampproject/toolbox-cache-url":"^2.3.0","@ampproject/toolbox-cache-list":"^2.5.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.5.0_1590752910027_0.12232485019295458","host":"s3://npm-registry-packages"}},"2.5.1":{"name":"@ampproject/toolbox-cors","version":"2.5.1","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.5.1","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/master/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"e5f0aba7218663b8e052bbcf5f69b734ec151883","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.5.1.tgz","fileCount":5,"integrity":"sha512-1R6fTUb//cT+JAWUnrMAEfe/u6PKDa41H5IV0bFPjSKrYwK9u1R8tAC8qxKC1mluNfIoCbEDtv6DKE14QzcGgg==","signatures":[{"sig":"MEQCICV8DeBsLCrH+qai6dO4cGmPSuDAEhv8jtlOsPFGt09EAiAniiNScG47M1ohywMJTf56c9tc7vghGmi1UY1HUoei9Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22454,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe3zquCRA9TVsSAnZWagAAWV8P/RCb/LU787Mc2GR7RT6t\nBjW6wXt08EryhIwNvchyJKLGHjJ/5PzYQ6z6wF8NQKPHns32bw10TkTAS/1L\nX+bA/BCKoD6vL+qutBEKeJMMv0L8w6Z0P5DexFUxRnEIhJ6avWTfElJ3bc3E\nPoN85MlwRA2Jzfy6AYkpuaf4cbAdSWYyAg8vDlfHUnn45HjuwAsrSRdA1VBW\n9YIn6oS1VY/yhhIC1f07Ki3ylVreaOJMUYpTVHxhITbaI3Scy1E8xl8tbFXh\nKC3TjQnZpishmRAKCdSlfFiMZvmtor1/7p3w5fC3yoBsCPXQB2Jrwnn61Gcf\ny4mzKZawzZ7ZGuMKR9gaWGendd6z1gY3Mr3fFKw8I9bXofe85faGj58cNIhV\nkBmC0ssUvqp/PQgjvioSsEgJM6Lo2XuifPuGgo9LKrvnq3Xy5VFeFSYxux84\nlmwoFOor2iEks3tklbb+Tw6vIbYKKxVkZ41aSQ8wATL77DwxAXV9Ls8LkZ/Q\nGfhyNbq/m8siq1/H6H+jTE/lnup4ElnSbrcrQlHQGf/TVlvvh4oiBuNN8e1e\nJwKfdSUwCaYesXPj6tOaVHPTP0x3YrO4qK5iq4ROu7MdjXFeeLfosYmp4DIK\nMJWSFf9V+X4staMT/wIVEwxRoUrDS4Z/gUFRyHewKuT2lkdciIz3UDUEp+Nk\nTLiD\r\n=edYD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"f92ba13281ecf3e624ee8285f2deebee18d580bd","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.0/node@v12.16.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.16.1","dependencies":{"@ampproject/toolbox-core":"^2.5.1","@ampproject/toolbox-cache-url":"^2.3.0","@ampproject/toolbox-cache-list":"^2.5.1"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.5.1_1591687854329_0.3103749775932154","host":"s3://npm-registry-packages"}},"2.5.4":{"name":"@ampproject/toolbox-cors","version":"2.5.4","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.5.4","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"8068ab2ce0b5fac72ae01ff01d39c117a86149cc","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.5.4.tgz","fileCount":5,"integrity":"sha512-7utA1bfeQXjJ10YMqXDUok401UPE6Sp/zKMAHp5vXGlcEzUA9n0a8nyZThp1QMcgTjigTBci5b9sjGF5wufLDQ==","signatures":[{"sig":"MEYCIQCW/xCiy5a5/tzNjuHPqoSMqwtDigPbPfcpnLCB7+JNSAIhAMJP4Ll0KHEivLzXuDEvaIqNMd0JMxmJamrkm7XGuZQG","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22452,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe8QvrCRA9TVsSAnZWagAAJdEP/iXv9Ucxt79Pj0kkARVF\n3AspC8quVw31QwNlGWNMVD32xSSY57DnWtYpkVZpBQcM1ZUDGWVcwgve7y8b\nMc/lBPA+wL9ZkSRMXB1+eV0RIJCpFPY858qL+u0RdTuYlLRhQHVPu6GJhVrY\nJvIbEn4AK1Qd3FMGzhhlVsZNeMqOyAFpSNre0VcfbuVGryM+3YtO4YkKXwZA\nxj65dOghmIOSOUZP0bak0rU5aM+2uC5Q/qoUV+wNyWsH9fLw4x47hoYkM0mZ\nTTmcUpWdGqif0qcousNONck2Aig0N2Z0vV60t5pvjCgF3hp6A2kiJ016bd5D\nxByqd3lg/m+6XO2FefFU8g72yoGPR+D8+1YWd7kNrl+6ujzWluUOGBgMZLzN\nH9iNr6ZWeagIdXSdTGRAreVgidyFatyGU/Rk8F80BvuznNxktbcIiB6yfSup\nAxu2eri+mDtPCb63kapKnD0nYNnOLKka5MdRghPsY4f7sL/veROlx6aBfgA2\nOCyJ/vtG/ZbE3i7MU18fuQdq4707mO0UwK+o0F2+PMLoQmq4ntcQCYEOoUE+\nle7sVYBSzzOigQRftZylkNWrJbBrGNA70K/jWvnFKZievTvun0CquEoKLAIo\nI92czH92JaU0y206x/RUfmyOATeLRCG6cHcQZfTXAQ/rd9D8rg1/J391J7u8\ns6py\r\n=2AKf\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"c194eb829c2d0d4cda21c961107d73bd7528f53f","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v12.16.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.16.1","dependencies":{"@ampproject/toolbox-core":"^2.5.4","@ampproject/toolbox-cache-url":"^2.5.4","@ampproject/toolbox-cache-list":"^2.5.4"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.5.4_1592855530984_0.7029143354077678","host":"s3://npm-registry-packages"}},"2.6.0":{"name":"@ampproject/toolbox-cors","version":"2.6.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.6.0","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"4a2956d857fa3706c59668f633cf776b2cce546d","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.6.0.tgz","fileCount":5,"integrity":"sha512-4nfOVqOrLnV8MVfgpVG9/vOqguX+95cEI9V2hEu6SoPEoFBsd6qw1lw3zlt//uw6XOAnmfO4nvJ59+fvVYImyQ==","signatures":[{"sig":"MEUCIAO7PDk206gysuPrWP2DVo2DnIuum4m8jDb9ddSoS+fyAiEAoVH/EkGAoiU2HIo+4EeFvpD48XQ/O+b2wWA5g94WUok=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22452,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfMUETCRA9TVsSAnZWagAAJAAP/0dbe/kkLmlxTZf9PDI5\nP+I3NSxAtw7/wWLyH46i0nXSpj6G4GMvk3UzYPAgiliKf3kpKCWgafzDD6rR\naljDYvgRK1o/6o3QpI8mkGDyNBDUyRYdVZAi9Q67AYoQjr8hoCrkIS1HYC73\nn0mZT48lV8O9OjEpU2gedMZdcKurFjDuJJhG4/EmOa7wk6DaUCpos+2kA4XC\nUMQuRyvYYA30PVebB50znvhFyLGbqmHMGrGHgvPGTJtC3FVljwsuLUaCCcIf\nuDZEpQo/bl84REsdIJFpwJ0PSjT3TR9bt/oNcn0UXQLYbSZLni1oi50LL7WQ\nqc1qetJcYvcx2dCscpQijK2+Nu0Ks6jfkpc+n/7Y6o4q4rq5ctSRchEXO1fR\nD7sW5/M7m6SNVPYICaCNTdLmaEZ0+Dgam3XRHOJAP5hN0IbsoE8BOrlxoVnK\nK2QNeVlFyJ2BNKx5Jcjejk5LCdj8arQ2Gs0oXEPGtBvXdGYY2CwffN3YKz5W\nmMpkWHfDM1taGJyIZkIrsYxnA+69wWpTOK/9pxUcY0IQYBrq89HWbjD2Yi+i\n3UJHJgyT6rjsCFbj7suz3BeycCZsIt2l1f94s+8Eg3Im3jzrFKbA5OM3b9wH\nST1vDPCISN47z0Idh0Iwoshmx2gq80/SKugITGYbVR0+epFKO3tgYSzIF4Mp\nRFla\r\n=R7TP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"1e47f01b6630a01581b7df014b76d9ba0f68542c","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v12.18.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.18.3","dependencies":{"@ampproject/toolbox-core":"^2.6.0","@ampproject/toolbox-cache-url":"^2.5.4","@ampproject/toolbox-cache-list":"^2.6.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.6.0_1597063443209_0.30524373902611246","host":"s3://npm-registry-packages"}},"2.7.0-alpha.1":{"name":"@ampproject/toolbox-cors","version":"2.7.0-alpha.1","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.7.0-alpha.1","maintainers":[{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"choumx","email":"willchou@google.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"samouri","email":"jzfisgreat@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"9d2e8b8f7a02e2fd2a003af8f7475ee6d5b45e6a","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.7.0-alpha.1.tgz","fileCount":5,"integrity":"sha512-66PXYth/J/+G1fBbw6qs3RGMsyMr96woxzLBnr/JLm1D4shZ0NujBbZJy8N3iNnHR4A/Eq3MgdN3nI6sAvVS3A==","signatures":[{"sig":"MEUCIBNyYBHKNBku2++JW+9kGw6vdU1FCbnXESQVEk+ZtBfeAiEA8V823/72jQgav+LJgC6UxmPMMvCm992hVBud/yqXopU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":22417,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfPWbdCRA9TVsSAnZWagAA5+cQAIPCf2y0uZG5xDWF5uJX\nad90lMJr/D4aR0Fdqu33XJljCPzY64+MTrL1MEm9DTN7hbbXhlDz/wX0iw9z\nnp+0yVHpHtywGcSdWejqVyxho8XwqbrLoRaVomr3G8T7p00NFACC7y58DQ1u\nA5zfGeTZi+JLHCDeAAQraaTle78LdThHss6Dj0AE7gYWo0ZtIG5STLkz6Eas\nu6ZANhDxKuZyYnbiV2o6uewhLx4kwovz1iTPQNFtGuJL36Ry0Weby1JHfnp9\nd7L3uTpBa29bhIYUsdjBXYMRMF0Cunq3WAVyci9xYFlG7Dn9M1+TSsiLuB2l\nKSQwXHF75/wXKUPMJ0nQXe0OT+G228Ib5oIbO0Y+32/k85zzikb7PSg6EWXL\n01Z7vA2/u+ZxHFxy3XQCPUOxr6Z5F6ZdIc5WKlYiYWwM1UbCo81RNrUysVWJ\nTbwvOzjtp0X59MK/e+KOXOqSde5YX5dKO0Re4TCGy7sjh0w/oMs/8rmJcQGW\nunYnJfrXdfi6h+KIzWCXzyIVOgzebPaYXT0KjiPsv/d/MSfLtxRmkqAHHzd9\nDekLAyKYybcGLd2dDbvIRrDkLCMWzZJIzRZWP2i+g+O4ylAb7Fkz2g5Y8pyP\n7qk1/9IgAMKMHkBcsWZ7kWRb7N9ij+UMY7J23lKDcfFOlJdauAKEuQMGGDQ4\ngpyL\r\n=NAKV\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"cdab35d31a9d431c66cda62174fb28aff93287eb","_npmUser":{"name":"caroqliu","email":"carolineliu@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v12.18.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.18.3","dependencies":{"@ampproject/toolbox-core":"^2.6.0","@ampproject/toolbox-cache-url":"^2.7.0-alpha.1","@ampproject/toolbox-cache-list":"^2.6.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.7.0-alpha.1_1597859548823_0.5956007155922212","host":"s3://npm-registry-packages"}},"2.7.1-alpha.0":{"name":"@ampproject/toolbox-cors","version":"2.7.1-alpha.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.7.1-alpha.0","maintainers":[{"name":"alanorozco","email":"orozcoalan@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"choumx","email":"willchou@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"bae7bbc1f7ac686ce2d05ee7ba0cf2699a5b26e6","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.7.1-alpha.0.tgz","fileCount":4,"integrity":"sha512-bRdZLw7UbL1q0BbUVhRdvo0YxsaHB/UNBi58yeVKrh/FtSSuF9AUJunmuf5H+CN3pLmkCPu4L0D/1NyhBCmhIA==","signatures":[{"sig":"MEQCICGKyZLe/mIsXOcdyEknSs9GIwWOIuIekpm/e8CxTPk8AiB41aUdqnIugk+df+gqoIkeq6Y6TtORPP3jcGfAyBDk9Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":11836,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfxpXwCRA9TVsSAnZWagAAvKUQAIhCLSJH5fjIF/n4qDkI\nSwinmuu8JCFDN8TAW3aHOLbULp8O+1XvDTS9L55Nrl06LBlquIHLpL+p1/FZ\nHcsx47Fnciv6fLe/TYU3UEbtTWzprLbv79TbreKN2A4dWd7bB3kkOv20Yunz\nt1kDhmaEp/8oGgn6MHorv95nhxgjrJLA4XEEUMPIOEsNq7dWPryTQgqGRcnE\ns/Hu+gveXK7Cnc2dSs+ak4/NZ1NBD/PhzoH78bjtcy9YxWYe8p/2vcd5HoTx\nf2duyg49IXnrwb+k9/i9V0tuRIcwDB+KSf+MLeVtG/5U5qnY1jF0LQ8Ry4U4\n9OoaOlnCWaxP/Z0Y+IPLrYT5hwtCpRxaeWrodI4Z1hTxuFxDtcSPH38Trbjh\n4mmlqC3Cah6zrbSwNotYBc/OWTRmWvzQjvugcRzhx5IfOAF1A1YDJO6hmLMl\nLqSUq3W4YTY/bfjGaWVO6bOa13UYnMcHIO8l6rPLAQ7mxtdhP6K2RLjaQXNz\n0aPBjHxZtf9FFSPVMchRiM4zvqRfLKt8XIXRETXXBsYI9/1WmbVoglKAqv/V\nQFNma2mHS1H15Qc4P6MaZ+ThoAdFU9PPSTZ3v9iDpdpfkaCvPWaKJ3g9xaXs\n65Cj06qtudBx0SLQnxy7lkOXF1n8JuMwCeu+6cswSRCv5BfNfxAWbfNovGdm\n6sOJ\r\n=4jEF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"c26612cc3d7408fdc1451bcc8e0fecd67ac9661d","_npmUser":{"name":"patrickkettner","email":"patrickkettner@gmail.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"6.14.8","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"14.15.1","dependencies":{"@ampproject/toolbox-core":"^2.7.1-alpha.0","@ampproject/toolbox-cache-url":"^2.7.1-alpha.0","@ampproject/toolbox-cache-list":"^2.7.1-alpha.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.7.1-alpha.0_1606850032041_0.9943959358359344","host":"s3://npm-registry-packages"}},"2.7.1":{"name":"@ampproject/toolbox-cors","version":"2.7.1","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.7.1","maintainers":[{"name":"alanorozco","email":"orozcoalan@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"choumx","email":"willchou@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"115fa666049c7d8370674797e44facfdbfa2dac3","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.7.1.tgz","fileCount":5,"integrity":"sha512-t+p/C4N+v/K6MQQNEg16suxf3lUjVuE0jj4Ugf920nTkMRnQmKcZDOMkKbTRX9QJPmJwb5Cao43gE5gz+0xC9Q==","signatures":[{"sig":"MEUCIHtEYdZCeKLes9J5q8zH05hLI+rrQEvbOf3z6s4DQMpmAiEAv1flJdUDlhVSu22gUM0SjqNGRfKw7zvZJsxUjlqXPzo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfx6rECRA9TVsSAnZWagAA1uoP/j2x1YWYYOSkhPHOF6ty\nB/c84+blbL7c1/P6sub5pi1LAfTFzrebsO27Ah2wTJDIkHWvxeGtw7SRtpQQ\n76kbUNW6Q0itP0ePyWPN2fvB5c/Ie/VF5ZyJYDsaoORH8XBPQuKY/lZUILbo\nEJ2g28nOQWrFzlb6pvNG7oMk4gnlJLMJZsBJkS/u3Tco9o5OvoZwPlfS1QGY\nT7k3rWKm4X0Qc5I/zHE08mvtVH0wCKkBH8zhtiTxl2HbFbX1lf7Y4F0BFPoV\nOptFzUOBLcSMzSbxLlFxznvgSEewRboIZgC7tnrDU3rY+ghrrWj+KlL2jlIb\nHvy6GulkY3/o91EB2fMlbLnm7yXPu5OhX8WzyBGZPZtKKYCo7tuaXRZ27cGX\nKrAqhF2D0ex+yZkJVwI1k1GpRkAap0YXRHpIMxB3boKqka9GSEkLbV70ff6i\nvW+NTDvif4QxhwJq0xHGg4WGx+EZN9tJEV2PMJpJ+5S+S1Q/5SZujtzr9f7R\nM7oskSkSTGnbokg8qThB6BdVilA8lUlpmKUmJ3vCMRvXmHWs8DAr9RdHfbwJ\ndkzMP9o4byWSpV9PdEFXRseqOC1+S/n96+p6gGD9XzRs8cc7PakqkH5NrQcX\n3OpRdJ8ebcQEZ+KV86h4hUA/UbOerUmdSigp1yhQqNFm/e7u2Y/v1hf6mSDe\nZaL9\r\n=q6IG\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"9b159391d776396512b01ec250fa76941713c763","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v12.18.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.18.3","dependencies":{"@ampproject/toolbox-core":"^2.7.1","@ampproject/toolbox-cache-url":"^2.7.1","@ampproject/toolbox-cache-list":"^2.7.1"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.7.1_1606920900285_0.2995647835841637","host":"s3://npm-registry-packages"}},"2.7.2":{"name":"@ampproject/toolbox-cors","version":"2.7.2","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.7.2","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"0daf45a1e41e85fcef761bb9d831cc3abf3c189a","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.7.2.tgz","fileCount":5,"integrity":"sha512-ax7us/M40QPeudgYxMS81E3JknuUo5lpT5naT26AOlqDA9PGNxs2linWuu0Cp4p4ygyv9EUxqLvIJHvVFPM9nQ==","signatures":[{"sig":"MEQCIAt/8HV1GzukJkvFBAJM4hRjxN0OGgP8vMZCcIVzpQTHAiAeBLvoQGE2goOHEIO4B7cJ+vcUzwxxEc6AwtSOQuFtAQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf2ROgCRA9TVsSAnZWagAAk/gP/2CTu1QlFl6tHEZraV3Y\nqqqqL//5ZERSb+stMFj/5HQSw18MJkjDJEOUz3oOZwSDOgW//xa9odLrubSR\nsxJQcJ52Cr8Bbzk0izbThRMKEGa2sz9jD9FzNos1zcEY6zARS8oY7phvwfGI\nuhUbQl6BwJgotLfNH4lx61Kj12P6SnpVzV8q0QXygyMvBsCF32MX095LtfKM\nykKNOoNiEtMKlyl7mcBsOE76QRLwKIy2Y9vZivOb4ZzLZZbepXlujqH0z2hW\n3qEDC1kejyZm8cA8uEokACmnSjThT28LijmsA/B9CHDIfBCG+7sie2MtyXEf\nxrOzBqWnwVNCI077GjRMXQwu8c5YDg6YUS7ZVN1cUt6IEXAGKvgAGvlzomlj\nNgz32mXosML+n2l4rIk0anjY/JOh0/e83UzUQHjAT9qiWy6gX0KAF4/y9E+w\ni7oJYu9DNJdGdblnZFpj25f/ISaNWXI/+bsYn7vc13dWDJTaxK6zkpssDeZV\nM8XcJea2WDQzYaFyJuwYJs+cNHM5Pf1FNdvph0Q9owtlSkEAXVIVBYlh4njM\nLDTa0b3Sq+gDxw7uM5g4DkCC44JZuR3VX0JvHvqH3SRq0OI+kxmTmgAA3EfZ\nhFkaX8rMT6vMdOIic2EDnmwqnuP1SMHadCVXNdhd/IWVwfAU+fU1RSx9BCCa\nV2iI\r\n=UPWz\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"83d1d4290d9da2683596506cff266c68e618fa81","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v12.18.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.18.3","dependencies":{"@ampproject/toolbox-core":"^2.7.2","@ampproject/toolbox-cache-url":"^2.7.2","@ampproject/toolbox-cache-list":"^2.7.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.7.2_1608061856221_0.3099011626457324","host":"s3://npm-registry-packages"}},"2.7.4":{"name":"@ampproject/toolbox-cors","version":"2.7.4","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.7.4","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"2f16f8ec957908a33a0c9e0d39d40ae9205a0de5","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.7.4.tgz","fileCount":5,"integrity":"sha512-fgCAqdpVOHBGOjlPwEdqeQ4sAjur5JtyOuAszqGVsF0aXc8JvBMTKCtPdn1Obg7LDqYnVagamCb22QCboFPRDw==","signatures":[{"sig":"MEQCID9yaxUjF5emhb9juRux7zBOFmT9roEaGi0KVAc2m5/BAiAaelN0IErtlqSyqNQcHNHAe3gkh2lWhUFCmaQpq3De0w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23145,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf4y8VCRA9TVsSAnZWagAAYnEP/1hU+G8DEevWHawrZOn+\n/0ulgdxWsaUJ4lUg6K8s/NmluS0kGZp1ttOXGIijpbmVIvmIcnLj9v9fYBps\n5E9wd1DzOHEeXaMftlunCx7Dah/O8KuXZEjbiaWqhzngJka/TqxzDuD6okrI\nwdE1V+DUbt7RfKeX6szgFpI1ynuGEy0EFFPvUY/q/IwnZj3FzwckJU7+9TNJ\nmtS3MFU6L1kQGAIkfu9r+DG/WOfX08VjXjI4cY7iEqEHRkyJqS9pn50hJQKq\njgDPoeiU6R/qBlZi0KD3D1lC7p2Xij4eUgNGEb3r5VdsSVYydyISeT9TVcxy\n2ZRSnihMxwZqK+T4wEXsIM03euQrJNXrsNmNRTM+BV0DaIvcvBa62dU0SUpk\nUcdwyx4JyZ+Dasw+n2zydVqWXszKRKToLjJoqR27OM5PRP3qUigPo/97hsCM\neeoFT7U1TCVRjUCjxujHPovJKWtGma4r4tHD+HJJYfyIgPAJy2XL4Jmzudpr\nrNVxzrv7WGJG/VusV2iR+hAIFk8dm8D+tQB5V/5/fNXKCikNq1I0d2PXX3Ph\nSFePk13CMsjftG+GMiGziTekE9St6FCbIDXzJcrR5o+arUpvCQAStL6egizE\nf2JHfMr5Ce7tjf+2PHRyMfziQ4oC4ofg6CPctO3wscFMsiy/SqzEK31IYPGc\nZNbS\r\n=NHk0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"881ffbde5be5e78e039b132f0daae3a3598ae248","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v12.18.3+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"12.18.3","dependencies":{"@ampproject/toolbox-core":"2.7.4","@ampproject/toolbox-cache-url":"^2.7.2","@ampproject/toolbox-cache-list":"2.7.4"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.7.4_1608724245534_0.09295876227375577","host":"s3://npm-registry-packages"}},"2.8.0-canary.0":{"name":"@ampproject/toolbox-cors","version":"2.8.0-canary.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.8.0-canary.0","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"deab8e06d4851444588354f3e04551795ac28c4b","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.8.0-canary.0.tgz","fileCount":5,"integrity":"sha512-53Tk7B6mjrQy+j4WUcgsFTY1LomvjWdMJsng/i1iKutRk+e9eKxxQa8YN4XGupZUJ62Hr9TUoBjK9OWmJOljzA==","signatures":[{"sig":"MEUCIDa/poGIw3EmIfGkupJCZiSp7f9o8pftdsagt41IRju8AiEAlNbXbHWUo1mnSWc3O22r1EmwYUpN0YpAZs6OchEBUoI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23183,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgJrniCRA9TVsSAnZWagAA9bwP/jgM/1Bj1Du5uQDYABuD\nRMNQR2uKiH2WlgiVdbi4vkDzFpq5DTm2xlSNy4u42LS3vIl6P3EZ61oqo8+q\nYKaUtGon8gQds40OXstZWszxVOjrQG5VNRhVKPNNNWUf4ArYPLKZEZrBnmCM\nfubwFSFuXGtmhUiyN2SbUA1w6+LHDe3KGrD53xM0mMnGq5CR59OonI91ROtO\npsmCb1N5QDeS1OLNI3jAzmtWJOLDBVbHVP6vwQPjgeilA6e6vzKYDACLjnLr\nH1EF7S59lRUrniuhb7uCk9EQ2EnLYefGI3rWCdv/ohggJGnEbfXxP1b3HZWx\nua0ZBmWKUPfLyi7mp2/YAjH0nbQSOE4qXEd+z7Ht1Plo8xrIFVVUoCjqr1Ul\nHvVUGInE59xxAYKX0P/Lj5Y6Op1qsKUDc3ssVcpTD6MFFhX10iZFOtRZHhov\nywuJs43c0uQYTeWRdc7oqC/rdgi5p6qSq80n7IlVL/tWuhczld3/KyU4Tg+3\nL4PpctNTBMZCSEPknNRh7WLt1RXd3UDl8p9MNABQprmubr420D61evTXRr66\nYOZEo7xt6BdkRHWp/hiKKaao/Um7b5vG7FLKe4gx6uXphCzbqsWUa7dIDtwV\nZ7H1FUDmybf5kkaVKXn7wvAvqt0qO3nhpSzFmwLdcc+vBY2hFt1VAiVT7WJK\nAAeb\r\n=IFz2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"0ec5cb5ca31022687841bc344b29fa8e775310d8","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v14.15.4+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"14.15.4","dependencies":{"@ampproject/toolbox-core":"^2.8.0-canary.0","@ampproject/toolbox-cache-url":"^2.8.0-canary.0","@ampproject/toolbox-cache-list":"^2.8.0-canary.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.8.0-canary.0_1613150690396_0.7189962473090086","host":"s3://npm-registry-packages"}},"2.8.0-canary.4":{"name":"@ampproject/toolbox-cors","version":"2.8.0-canary.4","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.8.0-canary.4","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"89460df7f091ae36b8966960c9fc65dfa5fbd2b9","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.8.0-canary.4.tgz","fileCount":5,"integrity":"sha512-+tgN1At+7736RmmptD0h4w7DizzQeEYLRQuWHa+MK0CUtwLI5HoWOUpw3/Z2Z2v+PD9pzvbCg6P9rdchEgJipg==","signatures":[{"sig":"MEQCIFBqECq+O3f/WLISawRzKM2bQCM+VERHj6k74haJ3eP2AiBwUOrYl57ia70JNDpinZ/Pfs/PMxISKnWJKZeqgaX77g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23183,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgPjWUCRA9TVsSAnZWagAAaK4P/113QzPRoK1UilkokBTY\nDVc8KiC5M7B6R5iUVBBAGa0BOVG/xjZIGsCjVZlPB8WNjE+nN9cmsSQFZpS5\n174W82SN4w4YKX9eJe52TbCZwhfxzqiOxVp37H7Q6YPMPWZNYDlnoOHEBhp4\nQ8qIabglfR0cEAXTwq0ct+D4aNsEeMG861CLwvo4IIxyOa3W9dPyobLOmUIU\nXMxeunBvyukO3sZDkOl8xy9JYimqwdhd3paNhnkpBVVdwPZYuD/cVXXwFvpu\nih2gddBYx55iBAYpBwRlG5IxUWNAQ+xbd0ufQozmZ3Z71n3QBVYskM9dTsfh\nNoMkT5yL1qmeNnX2W5dJz5iPiORYSTpJc4c9u6Ca+uApsnpwB4Oji8Z3Zfn0\nh9UIb8JbOFun28HSfO2C0vxipCm5hMHlRpMAAMlvJ6X0KsoNGir1BqShgIbK\ncScPNoE9K8IefMZmu0CGbkSSbfm0i4UmGLM0t4T39YkN5tFyVmA3loAmKooU\ntFWvqTZsGiJbw+ErJeJnyf8qa9yMmhy6qUAIOF9UAwyWtL9NsAVyqdEPIoPG\n6gI0tfjMKr2jDpXx07AfPX+i1wOyo5LOYJqo1dUfT8r9g0/RTtp1DXkpuZax\nAdjBtMq/4FDvCuVQjKT+EbPY8E+cZ0adiziAWqHp4glLpk8P0E4DJTI04B2a\n1m8J\r\n=bYE7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"0c3af53a631fffeffbe3da1f2d626172fc996f1b","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/3.22.1/node@v14.15.4+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"14.15.4","dependencies":{"@ampproject/toolbox-core":"^2.8.0-canary.0","@ampproject/toolbox-cache-url":"^2.8.0-canary.4","@ampproject/toolbox-cache-list":"^2.8.0-canary.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.8.0-canary.4_1614689683549_0.8367730175877652","host":"s3://npm-registry-packages"}},"2.8.0-canary.6":{"name":"@ampproject/toolbox-cors","version":"2.8.0-canary.6","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.8.0-canary.6","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"d469c1646357d13ab5b09c248dab1575c7f0bcac","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.8.0-canary.6.tgz","fileCount":5,"integrity":"sha512-6WXcWj4WB0KC/78H1g6V4eL3jpfmxRa6nWLg+YBJ836dp+gjNkfJ76TDr+WmTJnIyVvBtONO9O2ZTTNHP02XOA==","signatures":[{"sig":"MEQCIA3JFwRQrze4/FEPzHmXxa3+vWMurftC5nxpPnHLomCYAiADY0CA0ZncLMQnTVYivtqlIlMoH7M+AzuJYOKDJXN2Xg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23183,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgU40LCRA9TVsSAnZWagAAKgAP/3cjqWx4G4NuVOXtfRfA\nyJkxCK/MPSwdDnTRNXJIiQ1NQ2uNjtL0RCEWoTQXnV+CDWfNyK1LLf+JS/pr\nkoZOCBy19SZU38BwuGFC8Ovnpoq/i2Mwz78GJ7xJEXq7kJKlv6V2lewzLBtI\n3+JgLxGbL+Ys6f4fIztXlTMDOQpgMKlvWL0sXsyzQgG4mm318k0AqMUiHZEm\nvm2LMwbiK/gDD0HBzbTvCHCHgjMfEIvCfQPRxAhkC9D2GcEV4hKs9IQyftFz\nDPM1EkdiTxBS+pyNS4e22GWDk8Yfg50nwqzI0ikh94JCElZYgrlapYQ605Ks\n99ah79KQURlO2WDD9mpu94P8KZhdqzZqMvgYqkg1uhaXYsyq5PrqR2vxR1KR\nN4mVKfT/cWCe9cPJZSubm16jhy700LF5GkAOk77QnIq1zWJnt9xdz2yQJedJ\nEOFLAkbsiJhcDlBt18JHqYXYQkdX9GAga7WQiK1B1OZ7Tg4wHAizRoWEbefz\nlSNve6aHIV+2Vw+k1mIxLdyMsdnkx6XhvOVUzil0Lb9TjOehTDhjT//bWzXd\ngCgBJyoLgMFU82mlu1aB+U1pQv5tD/qkT3DPgKR5oSRCtPqA/SDHc/Z3C/no\nCsDJGjkPwvGxAiJBTZRNnHnk6cO/tIaTp2pQVd6VrW/XoHmLwdKv0dvMunsQ\nSeEO\r\n=OoJY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"69468eb65804e741db4bfbd129c7c4dbfb4b7561","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/4.0.0/node@v14.15.4+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"14.15.4","dependencies":{"@ampproject/toolbox-core":"^2.8.0-canary.0","@ampproject/toolbox-cache-url":"^2.8.0-canary.6","@ampproject/toolbox-cache-list":"^2.8.0-canary.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.8.0-canary.6_1616088331159_0.7740199475020282","host":"s3://npm-registry-packages"}},"2.8.0-canary.9":{"name":"@ampproject/toolbox-cors","version":"2.8.0-canary.9","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.8.0-canary.9","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"5286ae54a2084297d6a29ed2190eab8076d0d305","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.8.0-canary.9.tgz","fileCount":5,"integrity":"sha512-wWjSkA/vYWAdCWoSFAGHOy9T48PDd4F8sgR0MGzg6mgxDEKpJx/eHh6IikM4Yq0ggCOinOX4K8Ck/kmFNn4R+g==","signatures":[{"sig":"MEQCIDikE/L+WyY1EaIEaDnawqlZCq2Uy5i18+6MT349TD2GAiAtu0U1Gt5vcucHCMgY0TD+Ua++yuTEgDrUlmRCrTAj5A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23183,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgWLFcCRA9TVsSAnZWagAAwioQAJuDMAKoJ1UQN/LCNvPj\n/C8IjNo9fiA6Cp9WqFJ2tgiliPOWzBYJ/nZuno0X1YYZ6yv2yHcMJJlWy9rp\nmpab+i3XdoKLcK9g/6BeRglJqHVxu/pvllFTmB/zEFhSQPb3fWt+6VE9Xn5t\nvdR351OwJMHQALmEMis5f8pHLqTpzpa4HYA6kqjH+QErvXityLoWcoBeO+z5\n5xJKWcHE/a4XGhhSfgCBi1kZHKD3GR1E9Gp8HZ5s0iGIREBBmuETYKoL4dD6\nGi/JRHQioJHycFsk4KmpDDDcUKIx4TX2dqD5riO3FK8UHxtZFon2CwY0Zh/5\nnishouDOTeC36tjvvvHy8eOGuq+xH3/UaHJeU4KkGz+cfO3nwaz+uToq1PGK\nvdtRxwYMTwa6aUvbDmQLJCbjEc1E9wy9JggGmiaBliL59JbiRApiC6CXkAKm\nqtowcfqQ9WW0pcXif+WwLQlys1f5qhN1DawruPPtvRmVLjYvRPOV7PB9720O\ne7PAlDCG/TT4zc57GG/zrwqVoX3KZfRSfW4We6lDByfJpnnufQXsf/lvLcaU\njEhLcbmhTwraCmi4H8GM4XAc9JgOhG1ressgTRU/aObDl78WzaGF0vLlSMpl\nTZcEINR2s9Nkb3Jq8YboLma3y6LJi6zzcWEHG5lhZsRu912CEEw4lmcpM6LT\nw7W9\r\n=JSfC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"0974deb66a4bf37062208de3f6dbeea1ba08fa36","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/4.0.0/node@v14.15.4+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"14.15.4","dependencies":{"@ampproject/toolbox-core":"^2.8.0-canary.9","@ampproject/toolbox-cache-url":"^2.8.0-canary.6","@ampproject/toolbox-cache-list":"^2.8.0-canary.9"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.8.0-canary.9_1616425308332_0.09716479319145677","host":"s3://npm-registry-packages"}},"2.8.0-canary.15":{"name":"@ampproject/toolbox-cors","version":"2.8.0-canary.15","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.8.0-canary.15","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"0f743855118f3154a94bbf4632b41a8cc3ecd84a","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.8.0-canary.15.tgz","fileCount":5,"integrity":"sha512-fh+8/bZb6obSurtT9WAT3y3LUpHTfoRBE1OW58DfXRDhihYGMC+g5bVMDypcOWhfiLHfD4FF+THy5ERCXemGRw==","signatures":[{"sig":"MEQCICqPYKDc5TGPcfSF5+pPtA9ZkS9uvwI12F1E/SgsdNT3AiAi7WnW0f6S2CY+iEpgXVwR2XjWB50XB3Ptqabz3nqvZw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23186,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgY4uECRA9TVsSAnZWagAAdycP/RyphShQkglFaXVaINB3\n1vGmLNDAUVT7G+0ABZPXyygoCPAtfXFlUY4eIOJB1WBPASjgGJWEreLxZwr4\nuN7mMqbTwvi+miX4hpDJspFMa4CCHLooIh6TnsjjgGwHrB34TwfnUvCqNCbj\nfK/8ePGR41caMrJt1o4PQx4Vp7GTtRA1EPlnggAB8pc37izINnv2+Sc3vzAz\nDZwHD7dNlSUxF/3Q0nS2AlataPmhZtPz6H2d0A8hluu3Wxgj1NJvOqGAOg1C\nCQGh98z55O3adqP9ifdVisBIt87bmtN/y9vdUctrdmwHZ6hBLwF2Fer6hzZZ\nzOtoAM3fRVH9vYGtI56+PDm2APUk0C1JbYo7M3t810npCT0ZIwlR81GVVsPo\nU7NHmA/F0hSDL67Eh+38+kXOJPv12+JUXrF4fFJpBdqrxeIzRQ/QMGZbdPiP\ncBAvaz6vcauf14Wqoi0daB76G9232peT70wADFTNtSyRuDE0K2AbyWp6/+WI\nlzohwUKyJUM/DouS89bu/xMy8wbU9MHup0V+Xr4EmUuV3nItoWqicl/Nyno/\n+yLH8rL5tLVeoqBQtpjIPFcA4lh6HuH464HRvygqsbYHC1CNATaHzwYftbi1\ntPPZs3VtyDe4M7020SBDMqQ0NzNb2w/+mFQyAumQc1x+GlHoyckttEu1tfyw\nFtRY\r\n=mAJ1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"082fd3256f3664fb016b47d2d1b965d47ebb3f53","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/4.0.0/node@v14.15.4+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"14.15.4","dependencies":{"@ampproject/toolbox-core":"^2.8.0-canary.15","@ampproject/toolbox-cache-url":"^2.8.0-canary.6","@ampproject/toolbox-cache-list":"^2.8.0-canary.15"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.8.0-canary.15_1617136516197_0.062375724839568436","host":"s3://npm-registry-packages"}},"2.8.0":{"name":"@ampproject/toolbox-cors","version":"2.8.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.8.0","maintainers":[{"name":"esth","email":"esther@amp.dev"},{"name":"ampprojectbot","email":"bot@amp.dev"},{"name":"kdwan","email":"kdwan@google.com"},{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"a962977c926e7ff10425a720730bbcf7d93fdf67","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.8.0.tgz","fileCount":5,"integrity":"sha512-+QU6RNWpFyXFF0Mn9XQL1voKaYtpvZWFNQ90ouUmGAdOce9Kgwv6p/UzEwEAj+e/jO2AZBU2DE6xledEDiquTA==","signatures":[{"sig":"MEUCIFC9lExXLN3eALUXCyKfhYmR9SAZIeRQSSe2aBpNEwCwAiEAshZl+rX1J8iLSwImyMcvFddvMDaY02mlkRKm00NJ7e4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgtPRJCRA9TVsSAnZWagAAVAYQAIpg+bWSjJ9X2wuuf8W0\nGuBxTLKNG/nCgtZaqB69tsvShZ6oCLCt7xWdWXrI9TL5NUCNSF6w3me5cIWT\nZG4l8L1iC00yOGWYjC7XhcXGQFqHCmFm106oZI0uoHnFqpYD+Ki6xvAnfYGa\n23tiIRMD5fjGbL+Kfd95CxfSfOkOovDGeB50s/mM/n27BKnY091WxlZx0p7w\njwk+Q6Ejx3AMABAQBYZ736Nzu50oUvDvlcwAn2va9EGyW/Jq3H90TDtluvnP\nSI1E6k+hbS1SptXTFb0NLuR/sz5EPVCSdKzjmIr+PQBM+UEDupFP3+4bGrQ4\ndTfyZ86SUEw4WbPvzC6S4wiZ0YHRETlTVSvC3ycXc15BEX+U0cgzYyEBbV7V\n2OLxk2Sbhq24usjg1uPThAPvk+QUfD+p23poi2ZN1D3n92C8at4YsbRvazqk\nNyTn6RPS1lTCvXmOiu6G7DDsAOGLTA70m0ciqJHnpI4+PoQOYD0SmPeg1DlO\nCEDAKm9iT3AamSsPReKRb+3tgo9a3jtud5l1eM5mZyRvp8U72AwYsW/aww8P\n6pkY9zZgqk8Z6yFwEBEO7JHLzymUWcz/ZMHMRsBNXS0I5lhUqUn9HLSVsu9L\nuzQr/pF0i1UIaWwU8SIHTyMQu6d0IBo9g6+7ZUN0nit3mwhN4JTxpdhujXbS\np5QE\r\n=6Tty\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"6103eb57765445355421826791361ac9ed9cf4d8","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/4.0.0/node@v14.15.4+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"14.15.4","dependencies":{"@ampproject/toolbox-core":"^2.8.0","@ampproject/toolbox-cache-url":"^2.8.0","@ampproject/toolbox-cache-list":"^2.8.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.8.0_1622471752560_0.9434656610659666","host":"s3://npm-registry-packages"}},"3.0.0-canary.2":{"name":"@ampproject/toolbox-cors","version":"3.0.0-canary.2","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@3.0.0-canary.2","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"},{"name":"kdwan","email":"kdwan@google.com"},{"name":"ampprojectbot","email":"bot@amp.dev"},{"name":"esth","email":"esther@amp.dev"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"4e7cf1052ed11455b59d863dd1ed89af551996b6","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-3.0.0-canary.2.tgz","fileCount":5,"integrity":"sha512-J254+HmKBXuC2HDhv2afTtJIMzCd6vBAQzU7wy4/jevU5VzRf1+GM/QAXs7uYZKyIbq6DoDfsP3ihCuWOD+Xpg==","signatures":[{"sig":"MEYCIQCzGtPp8U9CI0OHmuc3xqKeHB1hmJ3BfqeMFBdHCF8daQIhAPeoUVhnuNULdhtH3k1P8wh/KPq36D5sGInIrLjiZ47z","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23172,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh3eqcCRA9TVsSAnZWagAAE5MQAJtSeobOZWxY3I43hSEx\nzgP+QHLzeV2as+B8fagDb572/o8E87R8IzmHypmoKCkPOVS+wDK9SAtjpVfJ\nJY8NPZK2xHMe2aNQYtUdnFCdLMBXUtug4+PinVnAyIIBARausLcaoN066564\n3I/+SusKPMAJjx5oVe6Lx7ZxTTzZKOaOfmDn03mFxjIo1wDEk+jvVgFxc8jc\n81Mz73Sy2sr1CX6moep9qmh0X2Asasb3xfjXYM+hVi1Ng5a9E0UPu1y1Uc2y\n345Kcugq1fOe0wqlpJfUhf/C2Ecj318vrzfWq4cnk+mALIS0+PL1lzGS4WcD\nVjdJbNyvwNzYnv1Q0CK7dLaC5zowKO4A2PfZukQING1BQKWg3/BXEsM4UoHU\n6DaEZDY2vVVw+QLTfoQP1XFSuMUwb9PRlCYCezkM2T5Va0f0kJ5pvX94+7qL\nd8+CSp1rz77GSXXZzy8cStHIWFlrzoeREsBsdRVoMVjrVkR6L/RCbjnkdil7\nxtpzphW6Q2fDhARDcrf+fGhNXeeuL/H3d2j0O4z/VSURV2XniMgrZKGB/8s+\nnsSDgmjn1nYMb9tD9legnENiYXc+vo7eBq7WyIP/JOxjYa20xVc1M8K4VnYm\nGSd+fUFXw3dQNVY6SdPQmGO3MfEEqvb9gbpdf/lGHVtruPQO/IP5rHKXg5XY\nh5Fz\r\n=5DmX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","gitHead":"0f63a77e8081f0fb7d6b63280e2fd8701836c4f9","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/4.0.0/node@v16.13.1+x64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"16.13.1","dependencies":{"@ampproject/toolbox-core":"3.0.0-canary.2","@ampproject/toolbox-cache-url":"^2.8.0","@ampproject/toolbox-cache-list":"3.0.0-canary.2"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_3.0.0-canary.2_1641933468722_0.9182542479813007","host":"s3://npm-registry-packages"}},"2.9.0":{"name":"@ampproject/toolbox-cors","version":"2.9.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.9.0","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"},{"name":"kdwan","email":"kdwan@google.com"},{"name":"ampprojectbot","email":"bot@amp.dev"},{"name":"esth","email":"esther@amp.dev"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"d43f979701445f483d188367a13a11cf9077f1f2","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.9.0.tgz","fileCount":5,"integrity":"sha512-sDBTW4+r7fSU2w2fQZ2B6y6askdXERi2ezksg3IiJh9VOLZUCdSD9RbiIeVc4CbOSc5G59o+HIO2mbvxuMNk4g==","signatures":[{"sig":"MEUCICFOceM7+sdyIojSJo/Y6zqOkBwPtuQDkprnxOQtdpMJAiEAyOVbYqKyCcgoBws4Hw97F99REH1ZHGR6FFlbibc6Wlk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":23144,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJitNGjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqDBg//XU1YH4oNkpMXhpWyTgc7hmpUIZ4jHod++OhRgUxHQJ5BjdT4\r\nlaLE2NIxmAIbW6gymp+UbBvVAXs7dhT4HcHoZihJEQrtrvqm0+W4CsrWYsiE\r\nX2TAgdlSQfN9TyfD/RgBM/R97sP+wp/om8dcYDPsXaUXJze+YKxL8Keuqsya\r\nvQsQiUSYvXC7LbF0ACnrvdd0cbQQIT/lKlJw+0J65KXxvP99GocRLerFQwTO\r\nFnO18mwewWT1OEpKk9LLV9wdVdv1i9UI63gYWJw6dI2xd2jxEcwWu3BJsILl\r\nqAVmqoxYVSFgqIg4148Rb7eYr72vljUeLWVnCNtePd25I9u788fKCuNz5Pj6\r\noOGJ5CK58c0eL1HmI9m3FDBmOz83D+QACe+vp6bNBvPw2/AFuu20wrMMSpOV\r\n/YpoDPRSlaGwUrCKIisxWMqarRDfgkyzbqkuAX3nZR/qEo4RwVnJuubiWdyC\r\nzMAhErr7G7Va0l0qUBtw3rLDSKUlNlrGuPvHNjHopdRMhXAkeMlCIEzOPruQ\r\newC6tl5JHs7rE1LDDb0tTu3KEASxbXduHNs1ObmKfonip+myY3DIq0z3SP8Y\r\nlFD0S095YBqgMovU7Rqy2iIbHdkef0F4RAPVYJNOkXeWWhuvJ+8cAHRmMV3j\r\nkFWbx7z1r77k01Fcl0832kNy7u0lnfvmiBI=\r\n=F9wb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"0826825fd8c5f3abac821ebe87a318e70f33c9dd","_npmUser":{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"lerna/5.1.4/node@v18.2.0+arm64 (darwin)","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"18.2.0","dependencies":{"@ampproject/toolbox-core":"2.9.0","@ampproject/toolbox-cache-url":"2.9.0","@ampproject/toolbox-cache-list":"2.9.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.9.0_1656017315604_0.786459608223683","host":"s3://npm-registry-packages"}},"2.10.0":{"name":"@ampproject/toolbox-cors","version":"2.10.0","keywords":["amp","cors"],"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","_id":"@ampproject/toolbox-cors@2.10.0","maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"},{"name":"kdwan","email":"kdwan@google.com"},{"name":"ampprojectbot","email":"bot@amp.dev"},{"name":"esth","email":"esther@amp.dev"}],"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"dist":{"shasum":"19ee1369b0e4a3378c118b2664f7a32766f707f3","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.10.0.tgz","fileCount":4,"integrity":"sha512-IfQh9TAJuUY7I5ozmYpXDRJS49dbHwrS1QUnwtfKCsjahg3/E8rBeAzSDIuPaN+HbP6/cnc4Sip+LWztElbLDA==","signatures":[{"sig":"MEUCIBHpQWUT+K2TVeVs+27NZqYRYhhrAbc7FaxjsmMTxEEeAiEAqwM0TAxhunqscTdyAqhenK/2UHSFf15QJEaCjqn1xCQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":11805},"main":"index.js","gitHead":"6103eb57765445355421826791361ac9ed9cf4d8","_npmUser":{"name":"ampproject-admin","email":"admin@ampproject.org"},"repository":{"url":"git+https://github.com/ampproject/amp-toolbox.git","type":"git","directory":"packages/cors"},"_npmVersion":"10.8.1","description":"An express middleware implementing the AMP CORS protocol","directories":{},"_nodeVersion":"20.12.2","dependencies":{"@ampproject/toolbox-core":"2.10.0","@ampproject/toolbox-cache-url":"2.10.0","@ampproject/toolbox-cache-list":"2.10.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/toolbox-cors_2.10.0_1718320086869_0.24384317159406188","host":"s3://npm-registry-packages"}},"2.10.1":{"name":"@ampproject/toolbox-cors","version":"2.10.1","description":"An express middleware implementing the AMP CORS protocol","main":"index.js","keywords":["amp","cors"],"repository":{"type":"git","url":"git+https://github.com/ampproject/amp-toolbox.git","directory":"packages/cors"},"author":{"name":"AMPHTML Team"},"license":"Apache-2.0","dependencies":{"@ampproject/toolbox-cache-list":"2.10.1","@ampproject/toolbox-cache-url":"2.10.1","@ampproject/toolbox-core":"2.10.1"},"bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","gitHead":"6103eb57765445355421826791361ac9ed9cf4d8","_id":"@ampproject/toolbox-cors@2.10.1","_nodeVersion":"20.12.2","_npmVersion":"10.8.1","dist":{"integrity":"sha512-0AhcY1zenN57XWcygv1Pr2kV/WGUXneqUosCFipZfydr1qlbl8aDQv9BxFHCnTXArEyVIGn7N034xsVi8/vBfw==","shasum":"0c614dc811c5eea4866f5d22129ab627a35b6c89","tarball":"https://registry.npmjs.org/@ampproject/toolbox-cors/-/toolbox-cors-2.10.1.tgz","fileCount":4,"unpackedSize":11805,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDjQnAiwoOd+Zlbimz0dWe/+2BclZEkbQq1I82u5Z7IVgIhANtqSIcCrXB+sBDF22L8HswbzxQd1bG5LL5nCnNHlup1"}]},"_npmUser":{"name":"ampproject-admin","email":"admin@ampproject.org"},"directories":{},"maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"},{"name":"kdwan","email":"kdwan@google.com"},{"name":"ampprojectbot","email":"bot@amp.dev"},{"name":"esth","email":"esther@amp.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/toolbox-cors_2.10.1_1718325296261_0.7183295003916019"},"_hasShrinkwrap":false}},"time":{"created":"2019-06-10T18:21:00.372Z","modified":"2024-06-14T00:34:56.800Z","1.0.0-beta.0":"2019-06-10T18:21:00.761Z","1.0.0-beta.1":"2019-06-20T08:56:10.846Z","1.0.0-beta.2":"2019-06-20T09:40:55.945Z","1.0.0-beta.3":"2019-06-20T09:50:22.850Z","1.0.0-beta.4":"2019-07-11T14:38:13.832Z","1.0.0-beta.5":"2019-07-15T15:36:04.773Z","1.0.0-beta.6":"2019-07-23T13:02:24.164Z","1.0.0-beta.7":"2019-07-24T13:51:34.437Z","1.0.0-beta.8":"2019-08-01T09:09:06.261Z","1.0.0-beta.9":"2019-08-01T09:16:00.433Z","1.0.0":"2019-08-06T19:59:45.200Z","1.0.1":"2019-08-06T20:11:14.235Z","1.1.0-beta.0":"2019-08-29T20:27:47.154Z","1.1.0-beta.1":"2019-09-19T19:20:42.803Z","1.1.0":"2019-10-08T14:14:18.632Z","1.1.1":"2019-10-08T14:43:24.165Z","2.0.0-alpha.0":"2020-01-22T14:30:28.994Z","2.0.0-alpha.4":"2020-01-28T15:26:06.682Z","2.0.0":"2020-02-13T21:24:46.703Z","2.1.0":"2020-04-01T08:59:54.421Z","2.2.0":"2020-04-03T08:23:43.535Z","2.3.0":"2020-04-15T09:31:44.719Z","2.4.0-alpha.0":"2020-05-06T19:49:52.273Z","2.4.0-alpha.1":"2020-05-07T11:08:06.867Z","2.5.0":"2020-05-29T11:48:30.197Z","2.5.1":"2020-06-09T07:30:54.520Z","2.5.4":"2020-06-22T19:52:11.090Z","2.6.0":"2020-08-10T12:44:03.352Z","2.7.0-alpha.1":"2020-08-19T17:52:28.930Z","2.7.1-alpha.0":"2020-12-01T19:13:52.210Z","2.7.1":"2020-12-02T14:55:00.427Z","2.7.2":"2020-12-15T19:50:56.400Z","2.7.4":"2020-12-23T11:50:45.694Z","2.8.0-canary.0":"2021-02-12T17:24:50.560Z","2.8.0-canary.4":"2021-03-02T12:54:43.739Z","2.8.0-canary.6":"2021-03-18T17:25:31.308Z","2.8.0-canary.9":"2021-03-22T15:01:48.474Z","2.8.0-canary.15":"2021-03-30T20:35:16.342Z","2.8.0":"2021-05-31T14:35:52.688Z","3.0.0-canary.2":"2022-01-11T20:37:48.951Z","2.9.0":"2022-06-23T20:48:35.748Z","2.10.0":"2024-06-13T23:08:07.050Z","2.10.1":"2024-06-14T00:34:56.399Z"},"maintainers":[{"name":"ampproject-admin","email":"admin@ampproject.org"},{"name":"kristoferbaxter","email":"kbax@me.com"},{"name":"jridgewell","email":"justin+npm@ridgewell.name"},{"name":"choumx","email":"willchou@google.com"},{"name":"amp-toolbox","email":"amp-toolbox-eng@google.com"},{"name":"fstanis","email":"filip@stanis.me"},{"name":"erwinmombay","email":"erwin.mombay@gmail.com"},{"name":"samouri","email":"jzfisgreat@gmail.com"},{"name":"caroqliu","email":"carolineliu@google.com"},{"name":"rsimha","email":"rsimha@amp.dev"},{"name":"dvoytenko","email":"dvoytenko@gmail.com"},{"name":"patrickkettner","email":"patrickkettner@gmail.com"},{"name":"alanorozco","email":"orozcoalan@gmail.com"},{"name":"kdwan","email":"kdwan@google.com"},{"name":"ampprojectbot","email":"bot@amp.dev"},{"name":"esth","email":"esther@amp.dev"}],"author":{"name":"AMPHTML Team"},"repository":{"type":"git","url":"git+https://github.com/ampproject/amp-toolbox.git","directory":"packages/cors"},"keywords":["amp","cors"],"license":"Apache-2.0","homepage":"https://github.com/ampproject/amp-toolbox/tree/main/packages/cors","bugs":{"url":"https://github.com/ampproject/amp-toolbox/issues"},"readme":"# AMP CORS Middleware\n\n[![npm version](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors.svg)](https://badge.fury.io/js/%40ampproject%2Ftoolbox-cors)\n\nThe AMP CORS middleware adds CORS and\n[AMP CORS](https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/amp-cors-requests/) headers to all CORS\nrequests initiated by the AMP runtime. The middleware will only add these headers if the\n`__amp_source_origin` query parameter is present. All other requests remain unchanged.\n\n## Installation\n\nInstall via:\n\n```sh\nnpm install @ampproject/toolbox-cors --save\n```\n\n## Usage\n\nHere is an example using [Express](https://expressjs.com):\n\n```js\nconst express = require('express');\nconst ampCors = require('@ampproject/toolbox-cors');\n\nconst app = express();\n\n// That's it!\napp.use(ampCors());\n...\n```\n\nPlease note that AMP CORS does not depend on Express and is based on Node's HTTP Request and\nResponse objects.\n\n### Filtering by source origin\n\nYou can additionally filter requests by source origin. For example:\n\n```\napp.use(ampCors({\n  sourceOriginPattern: /https:\\/\\/ampbyexample\\.com$/\n}));\n```\n\nThis will only allow requests with `https://amp.dev` set as the source origin. Requests from all other origins\nwill receive a `403` response,\n\n### Origin verification\n\nBy default, the AMP CORS middleware will only allow requests from AMP Caches listed on\nhttps://cdn.ampproject.org/caches.json. All other\norigins will receive a `403` response. To allow requests from all origins, disable this\nvia the `verifyOrigin` option:\n\n```\napp.use(ampCors({\n  verifyOrigin: false\n}));\n```\n\n### Allow Crendentials \n\nBy default, the AMP CORS middleware will allow [crendentials mode](https://fetch.spec.whatwg.org/#concept-request-credentials-mode) for AMP CORS requests.\nTo disable this, set `allowCredentials` to `false`. \n\n```\napp.use(ampCors({\n  allowCredentials: false\n}));\n// => will not set \"Access-Control-Allow-Credentials\", \"true\"\n```\n\n### Allow AMP-Redirect-To \n\nBy default, the AMP CORS middleware will allow redirects via [AMP-Redirect-To](https://amp.dev/documentation/components/amp-form/?format=websites#redirecting-after-a-submission). To disable this, set `enableAmpRedirectTo` to `false`. \n\n```\napp.use(ampCors({\n  enableAmpRedirectTo: false\n}));\n// Access-Control-Expose-Headers: AMP-Redirect-To\n```\n\n### Logging\n\nFor debugging requests, you can enable the verbose loggin mode via the `verbose` option:\n\n```\napp.use(ampCors({\n  verbose: false\n}));\n```\n\n\n### Email Mode\n\nGmail has [specific AMP CORS requirements](https://developers.google.com/gmail/ampemail/security-requirements). You can enable the Email CORS mode via the `email option`: \n\n```\napp.use(ampCors({\n  email: true\n}));\n```\n\n**Note:** the default AMP CORS mode for websites is compatible with email CORS mode (only origin verification is no longer supported). If you want to support both, it's safe to enable email mode by default.\n\n## Example\n\nSee [express.js](/packages/cors/demo/express.js) for a sample implementation. There are two scenarios in which the AMP CORS header will be added:\n\n1. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `AMP-SAME-ORIGIN` header:\n\n```\n$ curl --header \"AMP-SAME-ORIGIN: true\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nX-Powered-By: Express\nAccess-Control-Allow-Origin: https://localhost:3000\nContent-Type: application/json; charset=utf-8\n...\n```\n\n2. AMP CORS header will be set if the `__amp_source_origin` query parameter is set together with the `Origin` header:\n\n```\n$ curl --header \"Origin: https://amp-dev.cdn.ampproject.org\" -I \"http://localhost:3000/items?__amp_source_origin=https://localhost:3000\"\nHTTP/1.1 200 OK\nAccess-Control-Allow-Origin: https://amp-dev.cdn.ampproject.org\nContent-Type: application/json; charset=utf-8\n...\n```\n\nIn all other cases, no CORS header will be set.\n\n```\n$ curl -I localhost:3000/items\nHTTP/1.1 200 OK\nContent-Type: application/json; charset=utf-8\n...\n```\n","readmeFilename":"README.md"}