mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 07:59:42 +02:00
fix(http): raw writeHead routes lost every header the security hook set
`reply.raw.writeHead()` writes straight to the Node response and bypasses Fastify's header store, so everything the `onRequest` security hook granted is silently dropped on every route that answers that way. The visible symptom is CORS. The hook emits `Access-Control-Allow-Origin` for localhost origins, so a page served from a local dev server may call every `/api` endpoint cross-origin — except the four below, whose requests fail. The security headers (`X-Content-Type-Options`, `X-Frame-Options`, CSP) were being lost the same way. Affected: `GET /api/events`, and `file-raw` / `tail-file` / `download` in file-routes.ts. Each now spreads the inherited headers first and lets its own headers win over them. Tests drive a real WebServer and compare `/api/events` against `/api/status` for the same Origin — the point of the fix being that the SSE route stops being the odd one out. Verified in both directions: with the fix removed, 3 of the 5 fail. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
---
|
||||
'aicodeman': patch
|
||||
---
|
||||
|
||||
Routes that answer with `reply.raw.writeHead()` no longer drop the headers the
|
||||
security hook set.
|
||||
|
||||
`writeHead` writes straight to the Node response and bypasses Fastify's header
|
||||
store, so everything the `onRequest` hook granted was silently lost — including the
|
||||
`Access-Control-Allow-Origin` it emits for localhost origins, and the
|
||||
`X-Content-Type-Options` / `X-Frame-Options` / CSP headers. A localhost page could
|
||||
therefore call every other `/api` endpoint cross-origin while its EventSource
|
||||
failed CORS.
|
||||
|
||||
Affects `GET /api/events` and the three raw-writing routes in `file-routes.ts`
|
||||
(`file-raw`, `tail-file`, `download`).
|
||||
Reference in New Issue
Block a user