Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(backend): harden FAPI proxy resilience and spec compliance by brkalow · Pull Request #8163 · clerk/javascript · GitHub
Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): harden FAPI proxy resilience and spec compliance by brkalow · Pull Request #8163 · clerk/javascript · GitHub
Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): harden FAPI proxy resilience and spec compliance by brkalow · Pull Request #8163 · clerk/javascript · GitHub
Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(backend): harden FAPI proxy resilience and spec compliance by brkalow · Pull Request #8163 · clerk/javascript · GitHub
Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): harden FAPI proxy resilience and spec compliance by brkalow · Pull Request #8163 · clerk/javascript · GitHub
Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): harden FAPI proxy resilience and spec compliance by brkalow · Pull Request #8163 · clerk/javascript · GitHub
Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(backend): harden FAPI proxy resilience and spec compliance by brkalow · Pull Request #8163 · clerk/javascript · GitHub
Skip to content

fix(backend): harden FAPI proxy resilience and spec compliance - #8163

Merged
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening
Mar 31, 2026
Merged

fix(backend): harden FAPI proxy resilience and spec compliance#8163
brkalow merged 9 commits into
mainfrom
brkalow/proxy-hardening

Conversation

@brkalow

@brkalowbrkalow commented Mar 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Propagate client abort signal to upstream fetch() to prevent zombie requests when clients disconnect
  • Strip dynamic hop-by-hop headers listed in the Connection header per RFC 7230 Section 6.1, for both request and response header copying
  • Support request bodies on any HTTP method (e.g., DELETE-with-body) by checking request.body !== null instead of a method allowlist
  • Add Cache-Control: no-store to all error responses to prevent CDN/browser caching of transient errors
  • Only set duplex: 'half' when the request actually has a body, avoiding unnecessary option on bodyless requests
  • Converted HOP_BY_HOP_HEADERS from array to Set for O(1) lookups

Test plan

  • Existing proxy tests continue to pass (82 tests)
  • New test: DELETE request with body is forwarded with duplex: 'half'
  • New test: Abort signal from incoming request is propagated to fetch
  • New test: Error responses (500 and 502) include Cache-Control: no-store
  • New test: Dynamic hop-by-hop headers listed in Connection header are stripped from forwarded requests

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved proxy behavior: support DELETE requests with bodies, reliable request-body detection, forward abort signals to upstream, ensure error responses use no-cache, and strip dynamically nominated hop-by-hop headers.
  • Tests

    • Added tests for DELETE-with-body forwarding, signal propagation, cache-control on failures, and dynamic hop-by-hop header stripping.
  • Chores

    • Added a patch release entry for the backend package.

…ipping, and DELETE body support
- Propagate client abort signal to upstream fetch to prevent zombie requests
- Strip dynamic hop-by-hop headers listed in the Connection header (RFC 7230)
- Support request bodies on DELETE (and any method), not just POST/PUT/PATCH
- Add Cache-Control: no-store to error responses to prevent CDN caching
- Only set duplex option when request has a body
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Mar 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eff9db8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Mar 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8163

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8163

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8163

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8163

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8163

commit: eff9db8

@coderabbitai

coderabbitaiBot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Proxy header handling switched from an array to a Set and now uses has() for hop-by-hop checks. Added getDynamicHopByHopHeaders(headers: Headers) to parse names from the Connection header and exclude them from both proxied requests and responses. Request body detection changed to request.body !== null; when a body exists the proxy sets duplex: 'half' and always forwards request.signal to upstream fetch. JSON error responses now include Cache-Control: no-store. Tests were added covering DELETE with a body, signal propagation, consistent cache behavior on failures, and dynamic hop-by-hop header stripping.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main intent of the changeset: hardening the FAPI proxy by improving its resilience and RFC compliance.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercelBot commented Mar 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 31, 2026 4:08pm

Request Review

@jacekradko

This comment was marked as outdated.

@jacekradko

This comment was marked as resolved.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.changeset/tough-ghosts-ask.md:
- Line 5: The changeset summary contains a spelling mistake: replace the
misspelled token "aobrt" with "abort" in the summary sentence (the phrase
"adding support for aobrt signals" should read "adding support for abort
signals") so the release notes/changelog shows the correct word; update the
summary text in the changeset file where that token appears.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: a8f5d12c-abae-4778-9f39-edecdb62d566

📥 Commits

Reviewing files that changed from the base of the PR and between 2809448 and 1fbdcef.

📒 Files selected for processing (1)
  • .changeset/tough-ghosts-ask.md

Comment thread.changeset/tough-ghosts-ask.md Outdated
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/backend/src/proxy.ts (1)

320-346: ⚠️ Potential issue | 🟠 Major

Don't restore Location after stripping dynamic hop-by-hop headers.

Line 320 strips headers named by the upstream Connection header, but Lines 338-346 can add Location back from response.headers. If FAPI ever sends Connection: location, this still forwards a hop-by-hop response header and breaks the RFC 7230 behavior this change is adding.

🐛 Proposed fix
- if (locationHeader) {+ if (locationHeader && !responseDynamicHopByHop.has('location')) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/backend/src/proxy.ts` around lines 320 - 346, The Location rewrite
logic can re-add a hop-by-hop header if the upstream Connection header listed
"location"; update the Location handling in the response rewrite to check the
same dynamic hop-by-hop set before restoring or setting Location: use
responseDynamicHopByHop (from getDynamicHopByHopHeaders(response.headers)) and
the same lowercase membership tests (HOP_BY_HOP_HEADERS and
RESPONSE_HEADERS_TO_STRIP) to skip rewriting/setting Location when it was listed
as a dynamic hop-by-hop header; ensure you consult response.headers and
lower-case the key like the earlier loop before calling
responseHeaders.set('Location', ...).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/backend/src/proxy.ts`:
- Around line 320-346: The Location rewrite logic can re-add a hop-by-hop header
if the upstream Connection header listed "location"; update the Location
handling in the response rewrite to check the same dynamic hop-by-hop set before
restoring or setting Location: use responseDynamicHopByHop (from
getDynamicHopByHopHeaders(response.headers)) and the same lowercase membership
tests (HOP_BY_HOP_HEADERS and RESPONSE_HEADERS_TO_STRIP) to skip
rewriting/setting Location when it was listed as a dynamic hop-by-hop header;
ensure you consult response.headers and lower-case the key like the earlier loop
before calling responseHeaders.set('Location', ...).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: ad9397c6-e66f-4599-85cc-262daab25aac

📥 Commits

Reviewing files that changed from the base of the PR and between 545a88c and ccf5a79.

📒 Files selected for processing (1)
  • packages/backend/src/proxy.ts


try {
// Make the proxied request
// TODO: Consider adding AbortSignal.timeout(30_000) via AbortSignal.any()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AbortSignal.timeout was added in Node 17. What other backend runtime are we waiting for support for?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good Q! Seems like it's also supported in CF workers as well, so I don't think we need to worry too much about runtime compat.

I'll handle the generic top-level timeout in a follow-up

Comment threadpackages/backend/src/proxy.ts Outdated
if (hasBody && request.body) {
// Only set duplex when body is present (required for streaming bodies)
if (hasBody) {
// @ts-expect-error - duplex is required for streaming bodies but not in all TS definitions

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

which definitions is it not in?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not present on the RequestInit type, I will clarify 👀

Comment threadpackages/backend/src/proxy.ts Outdated
Comment threadpackages/backend/src/proxy.ts Outdated
if (!HOP_BY_HOP_HEADERS.includes(lower) && !RESPONSE_HEADERS_TO_STRIP.includes(lower)) {
if (
!HOP_BY_HOP_HEADERS.has(lower) &&
!RESPONSE_HEADERS_TO_STRIP.includes(lower) &&

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] we could also convert RESPONSE_HEADERS_TO_STRIP to a set for the .has() method. But super super minor

* header names (RFC 7230 Section 6.1). These headers are specific to the
* current connection and must not be forwarded by proxies.
*/
function getDynamicHopByHopHeaders(headers: Headers): Set<string> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could probably add a unit test for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

covered implicitly in this test case: strips dynamic hop-by-hop headers listed in the Connection header from requests

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some nits, but overall this is 🔥

…) lookups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@brkalow
brkalow merged commit 849f198 into mainMar 31, 2026
64 of 72 checks passed
@brkalow
brkalow deleted the brkalow/proxy-hardening branch March 31, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@brkalow@jacekradko@dstaley