fix(effect): preserve Vary: Origin in CORS preflight when Access-Control-Request-Headers is present#2144
Open
kitlangton wants to merge 3 commits into
Open
fix(effect): preserve Vary: Origin in CORS preflight when Access-Control-Request-Headers is present#2144kitlangton wants to merge 3 commits into
kitlangton wants to merge 3 commits into
Conversation
…rol-Request-Headers is present
🦋 Changeset detectedLatest commit: bc66d03 The changes in this PR will be included in the next version bump. This PR includes changesets to release 27 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
HttpMiddleware.corswas silently droppingVary: Originfrom preflight responses whenever the request also hadAccess-Control-Request-HeadersandallowedOriginswas a predicate or a multi-entry list.headersFromRequestOptionsbuilds the response headers via object spread:Because both helpers set the same lowercase
varykey, the second spread wins and the response goes out withVary: Access-Control-Request-Headersonly. With dynamic origin echoing, that means a shared cache can serve a preflight cached for one origin to a request from a different origin.Fix
varyfromallowOrigin/allowHeaders.Varyheader explicitly inheadersFromRequest/headersFromRequestOptionsfrom a list of contributing entries, joining with,.The non-preflight path was correct (only
allowOrigincontributes to Vary), but it now goes through the same explicit computation for consistency.Tests
mainand passes with the fix.Vary: Origin(and onlyOrigin) whenallowedHeadersis configured statically.Varyheader for the wildcard origin case.Test plan
pnpm vitest run test/unstable/http/HttpMiddleware.test.ts(4/4 passing)pnpm check:tsgopnpm lint-fixpnpm docgen(effect package).changeset/fix-cors-vary-merge.md, patch)