fix(backend): allow PUT in CORS methods so browser can save settings

Found via live browser test: PUT /settings preflight was rejected because
@fastify/cors default methods omit PUT. GET/POST were unaffected.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-28 16:54:30 +02:00
co-authored by Claude Opus 4.8
parent abfee5a6fe
commit f59d6d1478
2 changed files with 22 additions and 1 deletions
+5 -1
View File
@@ -23,7 +23,11 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
const app = Fastify({ logger: false });
// Allow any origin in dev/e2e; tighten in production via config if needed.
app.register(cors, { origin: true, credentials: true });
app.register(cors, {
origin: true,
credentials: true,
methods: ["GET", "POST", "PUT", "OPTIONS"],
});
const tht = deps?.thtRunner ?? new ThtRunner({
thtBin: config.thtBin,
+17
View File
@@ -76,3 +76,20 @@ test("PUT /settings allows any model when model list is empty (Pi unavailable)",
rmSync(dir, { recursive: true, force: true });
}
});
test("CORS preflight allows PUT /settings (browser can save settings)", async () => {
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
thtRunner: {} as any,
listModels: async () => [],
});
const res = await app.inject({
method: "OPTIONS",
url: "/settings",
headers: {
origin: "http://localhost:5173",
"access-control-request-method": "PUT",
},
});
// @fastify/cors answers the preflight; PUT must be in the allowed methods.
expect(res.headers["access-control-allow-methods"]).toMatch(/PUT/);
});