Skip to content

Fix: Tor cross-onion CORS when Origin is null - #48

Merged
metalisk merged 3 commits into
devfrom
feat/add-onion-cors-support-2
Sep 28, 2026
Merged

metalisk merged 3 commits into
devfrom
feat/add-onion-cors-support-2

Conversation

@metalisk

@metalisk metalisk commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Description

Tor Browser sends Origin: null on cross-.onion fetches while the document origin stays the PWA hidden service. Reflecting Access-Control-Allow-Origin: null makes Firefox report “CORS Allow Origin Not Matching Origin” even on HTTP 200.

  • When the literal null entry is present in cors.allowedOrigins, respond with Access-Control-Allow-Origin: * for Origin: null (credentials: false on public routes). Without that opt-in, opaque origins stay rejected like any other disallowed origin.
  • Do not rewrite Origin from Referer: the browser CORS check compares ACAO to the request origin, not the referer; rewriting broke redirect flows that legitimately send Origin: null with an allowlisted referer.
  • Register Vary: Origin before the cors middleware so private-cached downloads (Cache-Control: private) do not reuse a * CORS response for a different origin when the package omits Vary for *.
  • Document opaque-null semantics in docs/guide/security.md.

Related to #46

Related issue

How to test

  • npm run lint
  • npm run format
  • npm run typecheck
  • npm test
  • With null in cors.allowedOrigins: curl -sD - -o /dev/null -H 'Origin: null' http://127.0.0.1:<port>/api/node/info → Access-Control-Allow-Origin: * and Vary: Origin
  • Without null in the list: same curl → no Access-Control-Allow-Origin header
  • Tor PWA → IPFS onion: confirm nodes show online after deploy with null and http://*.onion configured

Checklist

  • Focused fix on CORS behavior for Tor clients with explicit null opt-in
  • Unit tests for opt-in gating, no Referer rewrite, Vary: Origin on cacheable downloads
  • npm run lint, npm run format, npm run typecheck, and npm test run locally
  • Mainnet ipfs4/ipfs6 hotfix validated operationally before this PR (supersede with release deploy after merge)

metalisk and others added 2 commits September 28, 2026 19:20
Only emit Access-Control-Allow-Origin * when the literal null entry is
allowlisted; do not rewrite Origin from Referer, which broke redirect
flows. Document * response semantics for opted-in opaque origins.

Co-authored-by: Cursor <cursoragent@cursor.com>
The cors package skips Vary when ACAO is *, but download responses use
private caching. Vary Origin keeps per-origin CORS headers distinct.

Co-authored-by: Cursor <cursoragent@cursor.com>
@metalisk
metalisk merged commit 1946724 into dev Sep 28, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Enhancement] Support http://*.onion in cors.allowedOrigins

2 participants