Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fix remote pairing CORS responses - #2594

Merged
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses
May 8, 2026
Merged

Fix remote pairing CORS responses#2594
juliusmarminge merged 1 commit into
pingdotgg:mainfrom
ben-vargas:codex-fix-cors-responses

Conversation

@ben-vargas

@ben-vargasben-vargas commented May 8, 2026

Copy link
Copy Markdown
Contributor

What Changed

Adds CORS headers to the actual JSON responses used by remote environment pairing:

  • /.well-known/t3/environment
  • /api/auth/session
  • /api/auth/bootstrap
  • /api/auth/bootstrap/bearer
  • /api/auth/websocket-token

The allowed methods and headers are shared with the existing CORS preflight configuration so OPTIONS and the real GET/POST responses stay aligned.

This also adds server tests for cross-origin environment discovery and the bearer auth bootstrap/session/websocket-token flow.

Why

Fixes#1928.

That issue was closed, but I can still reproduce it on the latest nightly I tested: 0.0.23-nightly.20260508.230.

The backend is reachable directly from the client machine, and the environment descriptor returns 200 OK from curl/browser navigation. The failure happens when the app does a cross-origin fetch from the web/Electron renderer:

Failed to fetch remote auth endpoint

The server already handles OPTIONS preflight, but the actual GET/POST responses do not include Access-Control-Allow-Origin, so Chromium blocks the readable response.

This keeps the fix on the server side instead of requiring users to run a reverse proxy that injects the missing CORS headers.

UI Changes

No UI changes.

The visible behavior change is that remote pairing succeeds instead of failing with Failed to fetch remote auth endpoint.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Validation

  • bun fmt
  • bun lint
  • bun typecheck
  • bun run --cwd apps/server test src/server.test.ts

I also verified the fix manually by pairing two machines over Tailscale without a custom proxy.


Note

Medium Risk
Broadens Access-Control-Allow-* headers to additional auth and environment responses; while aligned with existing preflight config, it changes cross-origin accessibility for these endpoints and should be reviewed for unintended exposure.

Overview
Fixes remote pairing/browser fetches by adding Access-Control-Allow-* headers to the actual JSON responses (not just OPTIONS preflight) for /.well-known/t3/environment and key auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token), including respondToAuthError.

Extracts shared CORS allowlists into new httpCors.ts and reuses them in both the CORS middleware and response builders to keep preflight and response headers consistent. Adds/updates server tests to assert these CORS headers on cross-origin success and failure flows.

Reviewed by Cursor Bugbot for commit ea0ca88. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix CORS headers on remote pairing auth and environment responses

  • Adds access-control-allow-origin, access-control-allow-methods, and access-control-allow-headers headers to all auth endpoints (/api/auth/session, /api/auth/bootstrap, /api/auth/bootstrap/bearer, /api/auth/ws-token) and /.well-known/t3/environment.
  • Extracts shared CORS constants into a new httpCors.ts module so allowed methods and headers are defined once and reused across middleware and response construction.
  • Adds integration tests covering CORS header presence on successful responses, error responses, and preflight requests from cross-origin clients.

Macroscope summarized ea0ca88.

@coderabbitai

coderabbitaiBot commented May 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 412dbe92-489c-4f95-b40e-a05081e47d96

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels May 8, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 80fe9ca806ffa660a39d51f2c9e60cede7329957. Configure here.

Comment threadapps/server/src/httpCors.ts Outdated
macroscopeapp[bot]
macroscopeappBot previously approved these changes May 8, 2026
@macroscopeapp

macroscopeappBot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

Straightforward bug fix that adds existing CORS headers to HTTP responses that were missing them. The CORS policy (allow-origin: *) is unchanged - this just ensures consistency between the preflight handler and actual responses. Comprehensive tests included.

You can customize Macroscope's approvability policy. Learn more.

Add actual CORS response headers for the public environment descriptor and browser remote-auth JSON endpoints so linked web clients can complete pairing without a custom proxy.
References pingdotgg#1928
@ben-vargas
ben-vargasforce-pushed the codex-fix-cors-responses branch from 80fe9ca to ea0ca88CompareMay 8, 2026 08:35
@macroscopeapp
macroscopeappBot dismissed their stale reviewMay 8, 2026 08:36

Dismissing prior approval to re-evaluate ea0ca88

@juliusmarminge
juliusmarminge enabled auto-merge (squash) May 8, 2026 23:49
@juliusmarminge
juliusmarminge merged commit e0f3abd into pingdotgg:mainMay 8, 2026
12 checks passed
@ben-vargas
ben-vargas deleted the codex-fix-cors-responses branch May 9, 2026 16:38
ronak-guliani pushed a commit to ronak-guliani/t3code that referenced this pull request May 20, 2026
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: "Failed to fetch remote auth endpoint" error when trying to connect to headless remote server

2 participants

@ben-vargas@juliusmarminge