Skip to content

fix(server): allow localhost and loopback development origins - #36

Merged
jerelvelarde merged 3 commits into
CopilotKit:mainfrom
Sunwood-ai-labs:fix/allow-localhost-and-loopback-origin
Oct 5, 2026
Merged

jerelvelarde merged 3 commits into
CopilotKit:mainfrom
Sunwood-ai-labs:fix/allow-localhost-and-loopback-origin

Conversation

@Sunwood-ai-labs

@Sunwood-ai-labs Sunwood-ai-labs commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Opening the development UI at http://localhost:5173 and posting through Vite's /api proxy returns 403 (Cross-origin requests are not allowed.), because the server previously allowed only http://127.0.0.1:5173 by default.

Allow both loopback browser origins in development and support an explicit comma-separated APP_ORIGIN list. Configured origins continue to match the scheme, hostname, and port exactly; Host checks, cross-site request blocking, and owner-token authentication remain enforced. Outside development, an unset APP_ORIGIN continues to require the request URL's origin.

Changes

  • Accept a single origin or an origin array in the API middleware.
  • Extract origin configuration resolution and document development defaults, explicit overrides, and list syntax in .env.example and the setup guide.
  • Add regression coverage for both Vite browser URLs, production defaults, configuration parsing, restrictive blank lists, unauthorized origins, cross-site requests, unrecognized hosts, and owner authentication.

Validation

Windows, Node.js 24.15.0:

  • npm test: 35 files / 179 tests passed (including 29 origin configuration/API tests).
  • npm run typecheck: passed.
  • npm run lint: passed.
  • npm run check-format: passed with a temporary LF checkout matching Linux CI.
  • npm run build: passed.
  • git diff --check: passed.

The baseline Windows CRLF checkout and npm run dev portability problems are tracked separately by #34 and #35. No unrelated line-ending changes are included in this PR.

@Sunwood-ai-labs Sunwood-ai-labs changed the title fix(server): allow both localhost and 127.0.0.1 origins in dev and support multiple origins fix(server): allow localhost and loopback development origins Oct 3, 2026

@jerelvelarde jerelvelarde left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Useful development fix for localhost and loopback origins. Exact allowlist matching preserves the production origin policy and existing authentication/Fetch Metadata checks. Confirmed both documented Vite origins work and wrong ports, schemes, and external origins are rejected. Conflict resolution preserves the current gateway setup documentation. Integrated branch passes 220 tests and all static/build checks; combined tree passes 233 tests and the same checks. No actionable findings.

@jerelvelarde
jerelvelarde merged commit cdf86b9 into CopilotKit:main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants