NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2176 most downloaded on crates.io
Cross-Origin Resource Sharing (CORS) controls for Actix Web
Last release 1 months ago
24 Aug 2026
Ships unpredictably
gaps range from 9 days to 1.5 years
Nearly every release is documented
notes for 19 of 19 stable releases
1 version withdrawn
withdrawn after publishing
7 years old
32 releases · first in 2019
Add configured CORS response headers to error responses.
Implement PartialEq for Cors allowing for better testing.
PartialEq for Cors allowing for better testing.One column per quarter.
Cors is now marked #[must_use].
Cors is now marked #[must_use].Cors::block_on_origin_mismatch is now false.Fix Vary header when Private Network Access is enabled.
Vary header when Private Network Access is enabled.Add Cors::allow_private_network_access() behind an unstable flag (draft-private-network-access).
Cors::allow_private_network_access() behind an unstable flag (draft-private-network-access).Add Cors::block_on_origin_mismatch() option for controlling if requests are pre-emptively rejected.
Cors::block_on_origin_mismatch() option for controlling if requests are pre-emptively rejected.time dependency.Fix expose_any_header to return list of response headers.
expose_any_header to return list of response headers.time dependency.Do not consider requests without a Access-Control-Request-Method as preflight.
Access-Control-Request-Method as preflight.Update actix-session dependency to 0.11 .
redis dependency to 1.actix-session dependency to 0.11.redis TLS features to actix-limitation.actix-web dependency to 4.0.<details> <summary>0.6.0 pre-releases</summary>
Ensure that preflight responses contain a Vary header. [#224]
Vary header. #224Relax body type bounds on middleware impl. [#223]
actix-web dependency to 4.0.0-rc.1.Minimum supported Rust version (MSRV) is now 1.54.
Update actix-web dependency to 4.0.0-beta.15. [#216]
actix-web dependency to 4.0.0-beta.15. #216Fix panic when wrapping routes with dynamic segments in their paths. [#213]
Update actix-web dependency to 4.0.0.beta-14. [#209]
actix-web dependency to 4.0.0.beta-14. #209No significant changes since 0.6.0-beta.3.
0.6.0-beta.3.Make Cors middleware generic over body type [#195]
- No notable changes.
Update actix-web dependency to 4.0.0 beta.
actix-web dependency to 4.0.0 beta.</details>
Fix expose_any_header method, now set the correct field. [#143]
expose_any_header method, now set the correct field. #143Fix version spec for derive_more dependency.
derive_more dependency.Ensure tinyvec is using the correct features.
tinyvec is using the correct features.futures-util minimum version to 0.3.7 to avoid RUSTSEC-2020-0059.Fix allow_any_header method, now set the correct field. [#121]
allow_any_header method, now set the correct field. #121Disallow * in Cors::allowed_origin. [#114].
* in Cors::allowed_origin. #114.CorsMiddleware from docs. #118.CorsFactory is removed. #119impl Default constructor is now overly-restrictive. #119Cors::permissive() constructor that allows anything. #119allow_any_origin, expose_any_header, etc.) #119Transform::InitError instead of panicking. #119allowed_origins is All. #119AllOrSome is no longer public. #119allowed_origin_fn now receive the Origin HeaderValue as the first parameter. #120Allow closures to be used with allowed_origin_fn. [#110]
allowed_origin_fn. #110feat: Add handle_with_protocols() for Sec-WebSocket-Protocol negotiation #479
handle_with_protocols() for Sec-WebSocket-Protocol negotiation #479Sink<Message> for SessionMessageStream terminates on abrupt disconnects even if payload stalls (e.g. wss) #672Update actix-web dependency to 3.0.0.
actix-web dependency to 3.0.0.Minimize futures-* dependencies
futures-* dependenciesactix-web dependency to 3.0.0-alpha.1- Release
Bump derive_more crate version to 0.99.0
derive_more crate version to 0.99.0Nothing published for this version
Move cors middleware to separate crate
Your coding agent can read these notes before it upgrades. Set up the MCP server →