Files
Codeman/.changeset/sse-inherits-security-headers.md
T
Claudia 1a32e63765 fix(http): raw writeHead routes lost every header the security hook set
`reply.raw.writeHead()` writes straight to the Node response and bypasses
Fastify's header store, so everything the `onRequest` security hook granted is
silently dropped on every route that answers that way.

The visible symptom is CORS. The hook emits `Access-Control-Allow-Origin` for
localhost origins, so a page served from a local dev server may call every `/api`
endpoint cross-origin — except the four below, whose requests fail. The security
headers (`X-Content-Type-Options`, `X-Frame-Options`, CSP) were being lost the
same way.

Affected: `GET /api/events`, and `file-raw` / `tail-file` / `download` in
file-routes.ts. Each now spreads the inherited headers first and lets its own
headers win over them.

Tests drive a real WebServer and compare `/api/events` against `/api/status` for
the same Origin — the point of the fix being that the SSE route stops being the
odd one out. Verified in both directions: with the fix removed, 3 of the 5 fail.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 01:31:50 +02:00

655 B

aicodeman
aicodeman
patch

Routes that answer with reply.raw.writeHead() no longer drop the headers the security hook set.

writeHead writes straight to the Node response and bypasses Fastify's header store, so everything the onRequest hook granted was silently lost — including the Access-Control-Allow-Origin it emits for localhost origins, and the X-Content-Type-Options / X-Frame-Options / CSP headers. A localhost page could therefore call every other /api endpoint cross-origin while its EventSource failed CORS.

Affects GET /api/events and the three raw-writing routes in file-routes.ts (file-raw, tail-file, download).