Skip to content

Commit 13446a2

Browse files
authored
fix(seed-contract-probe): send Origin header so /api/bootstrap boundary check doesn't 401 (koala73#3100)
* fix(seed-contract-probe): send Origin header so /api/bootstrap boundary check doesn't 401 Production probe returned {boundary: [{endpoint: '/api/bootstrap', pass: false, status: 401, reason: 'status:401'}]}. Root cause: checkPublicBoundary's self-fetch had no Origin header, so /api/bootstrap's validateApiKey() treated it as a non-browser caller and required an API key. Fix: set Origin: https://worldmonitor.app on the boundary self-fetch. This takes the trusted-browser path without needing to embed an API key in the probe. The probe runs edge-side with x-probe-secret internal auth; emulating a trusted browser is only for boundary response-shape verification. Tests still 17/17. * fix(seed-contract-probe): explicit User-Agent on boundary self-fetch Per AGENTS.md, server-side fetches must include a UA. middleware.ts:138 returns 403 for !ua || ua.length < 10 on non-public paths, and /api/bootstrap is not in PUBLIC_API_PATHS — the probe works today only because Vercel Edge implicitly adds a UA. Making it explicit. Addresses greptile P2 on PR koala73#3100.
1 parent 1b43353 commit 13446a2

1 file changed

Lines changed: 12 additions & 1 deletion

File tree

‎api/seed-contract-probe.ts‎

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -163,7 +163,18 @@ const BOUNDARY_CHECKS: BoundaryCheck[] = [
163163
export async function checkPublicBoundary(origin: string): Promise<BoundaryResult[]> {
164164
return Promise.all(BOUNDARY_CHECKS.map(async ({ endpoint, requireSourceHeader }): Promise<BoundaryResult> => {
165165
try {
166-
const r = await fetch(`${origin}${endpoint}`, { signal: AbortSignal.timeout(5_000) });
166+
// Send Origin of the canonical public host so endpoints that gate
167+
// behind validateApiKey() (e.g. /api/bootstrap) take the trusted-browser
168+
// branch instead of demanding an API key. The probe runs edge-side with
169+
// internal auth; we intentionally emulate a trusted browser for boundary
170+
// verification only.
171+
const r = await fetch(`${origin}${endpoint}`, {
172+
signal: AbortSignal.timeout(5_000),
173+
headers: {
174+
Origin: 'https://worldmonitor.app',
175+
'User-Agent': 'WorldMonitor-SeedContractProbe/1.0',
176+
},
177+
});
167178
const text = await r.text();
168179
// Detect any envelope leak in the response body. A substring match on
169180
// the literal `"_seed":` is sufficient because `_seed` only appears on

0 commit comments

Comments
 (0)