fix(auth): bind current local registry and CORS

This commit is contained in:
2026-08-17 00:34:58 +02:00
parent c34e01e9b9
commit 94c2cd3709
15 changed files with 514 additions and 87 deletions
+18 -5
View File
@@ -698,16 +698,29 @@ export function sessionRoutes(
if (!await authorize(principal, id)) return reply.code(404).send({ error: "session not found" });
} catch (error) { return lifecycleFailure(reply, error); }
const rt = d.mgr.get(id);
// Add CORS headers manually: reply.raw.writeHead bypasses Fastify's onSend hooks
// (where @fastify/cors injects headers), so we must set them explicitly here.
const origin = (req.headers.origin as string | undefined) ?? "*";
// reply.raw.writeHead bypasses Fastify's CORS hook. Only a cookie-authenticated request
// from the exact configured public origin receives credentialed SSE CORS headers.
const origin = typeof req.headers.origin === "string" ? req.headers.origin : undefined;
let isConfiguredOrigin = false;
try {
isConfiguredOrigin = req.authPublicOrigin !== undefined
&& origin !== undefined
&& new URL(origin).origin === req.authPublicOrigin;
} catch {
isConfiguredOrigin = false;
}
const corsHeaders = isConfiguredOrigin
? {
"Access-Control-Allow-Origin": req.authPublicOrigin,
"Access-Control-Allow-Credentials": "true",
}
: {};
reply.raw.writeHead(200, {
"Content-Type": "text/event-stream",
"Cache-Control": "no-cache",
"X-Accel-Buffering": "no",
Connection: "keep-alive",
"Access-Control-Allow-Origin": origin,
"Access-Control-Allow-Credentials": "true",
...corsHeaders,
});
// Send the handshake immediately. Without this, Node waits for the first event body and
// proxies/clients cannot establish an idle SSE subscription or inspect its headers.