fix(auth): bind current local registry and CORS
This commit is contained in:
@@ -698,16 +698,29 @@ export function sessionRoutes(
|
||||
if (!await authorize(principal, id)) return reply.code(404).send({ error: "session not found" });
|
||||
} catch (error) { return lifecycleFailure(reply, error); }
|
||||
const rt = d.mgr.get(id);
|
||||
// Add CORS headers manually: reply.raw.writeHead bypasses Fastify's onSend hooks
|
||||
// (where @fastify/cors injects headers), so we must set them explicitly here.
|
||||
const origin = (req.headers.origin as string | undefined) ?? "*";
|
||||
// reply.raw.writeHead bypasses Fastify's CORS hook. Only a cookie-authenticated request
|
||||
// from the exact configured public origin receives credentialed SSE CORS headers.
|
||||
const origin = typeof req.headers.origin === "string" ? req.headers.origin : undefined;
|
||||
let isConfiguredOrigin = false;
|
||||
try {
|
||||
isConfiguredOrigin = req.authPublicOrigin !== undefined
|
||||
&& origin !== undefined
|
||||
&& new URL(origin).origin === req.authPublicOrigin;
|
||||
} catch {
|
||||
isConfiguredOrigin = false;
|
||||
}
|
||||
const corsHeaders = isConfiguredOrigin
|
||||
? {
|
||||
"Access-Control-Allow-Origin": req.authPublicOrigin,
|
||||
"Access-Control-Allow-Credentials": "true",
|
||||
}
|
||||
: {};
|
||||
reply.raw.writeHead(200, {
|
||||
"Content-Type": "text/event-stream",
|
||||
"Cache-Control": "no-cache",
|
||||
"X-Accel-Buffering": "no",
|
||||
Connection: "keep-alive",
|
||||
"Access-Control-Allow-Origin": origin,
|
||||
"Access-Control-Allow-Credentials": "true",
|
||||
...corsHeaders,
|
||||
});
|
||||
// Send the handshake immediately. Without this, Node waits for the first event body and
|
||||
// proxies/clients cannot establish an idle SSE subscription or inspect its headers.
|
||||
|
||||
Reference in New Issue
Block a user