mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 16:39:42 +02:00
`reply.raw.writeHead()` writes straight to the Node response and bypasses Fastify's header store, so everything the `onRequest` security hook granted is silently dropped on every route that answers that way. The visible symptom is CORS. The hook emits `Access-Control-Allow-Origin` for localhost origins, so a page served from a local dev server may call every `/api` endpoint cross-origin — except the four below, whose requests fail. The security headers (`X-Content-Type-Options`, `X-Frame-Options`, CSP) were being lost the same way. Affected: `GET /api/events`, and `file-raw` / `tail-file` / `download` in file-routes.ts. Each now spreads the inherited headers first and lets its own headers win over them. Tests drive a real WebServer and compare `/api/events` against `/api/status` for the same Origin — the point of the fix being that the SSE route stops being the odd one out. Verified in both directions: with the fix removed, 3 of the 5 fail. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
655 B
655 B
aicodeman
| aicodeman |
|---|
| patch |
Routes that answer with reply.raw.writeHead() no longer drop the headers the
security hook set.
writeHead writes straight to the Node response and bypasses Fastify's header
store, so everything the onRequest hook granted was silently lost — including the
Access-Control-Allow-Origin it emits for localhost origins, and the
X-Content-Type-Options / X-Frame-Options / CSP headers. A localhost page could
therefore call every other /api endpoint cross-origin while its EventSource
failed CORS.
Affects GET /api/events and the three raw-writing routes in file-routes.ts
(file-raw, tail-file, download).