Skip to content

✨ server: support multiple frontend origins - #1349

Open
cruzdanilo wants to merge 1 commit into
mainfrom
origins
Open

cruzdanilo wants to merge 1 commit into
mainfrom
origins

Conversation

@cruzdanilo

@cruzdanilo cruzdanilo commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

closes #1341

Summary by CodeRabbit

  • New Features
    • Added support for multiple trusted frontend origins for authentication and API requests.
    • Added an endpoint that reports the supported origins for WebAuthn.
  • Improvements
    • Authentication challenges, verification, and payment-provider redirects now use the applicable request origin.
    • Web API requests use the current page’s origin where applicable.
    • Updated cookie settings for cross-origin authentication while preserving localhost behavior.

@changeset-bot

changeset-bot Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f5785c5

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@exactly/server Patch
@exactly/mobile Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 7e06ab5b-262c-4c9b-b55a-1bf79af4d9d3

📥 Commits

Reviewing files that changed from the base of the PR and between 50d7434 and f5785c5.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f908435f-af9f-4e44-a527-5e4fa2991af0

📥 Commits

Reviewing files that changed from the base of the PR and between 9f9457f and 96702e6.

📒 Files selected for processing (3)
  • server/test/api/api.test.ts
  • server/utils/appOrigin.ts
  • src/app/_layout.tsx

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The server now supports multiple configured frontend origins for API routing, CORS, authentication, SIWE, and WebAuthn. Web API requests and provider redirect URLs use the current origin.

Changes

Multiple Frontend Origins

Layer / File(s) Summary
Configure and resolve origins
server/utils/appOrigin.ts, server/test/api/api.test.ts, server/vitest.config.mts, .changeset/cool-baths-hide.md
The origin utility parses and normalizes APP_ORIGINS and selects an allowed request origin, with the default origin as fallback. Tests cover origin selection and invalid values.
Apply origins across server routes
server/api/index.ts, server/api/auth/*, server/api/card.ts, server/api/kyc.ts, server/utils/auth.ts, server/utils/createCredential.ts, server/index.ts, server/test/api/auth.test.ts, server/test/e2e.ts
API routing and CORS use configured origins. Authentication and SIWE checks use request-derived origins, WebAuthn verification accepts configured origins, and /.well-known/webauthn returns the origin list. Tests cover these behaviors.
Use the current origin for web requests
src/utils/server.ts, src/components/add-funds/*, src/components/send-funds/SendFunds.tsx, src/utils/persona.ts, src/utils/useRampOnboarding.ts, src/app/_layout.tsx, .changeset/plenty-results-feel.md
Web API requests and provider redirects use the current origin. Persona redirect handling uses the server-provided origin as its fallback, and Sentry trace propagation includes the origin.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant WebFrontend
  participant APIIndex
  participant BetterAuth
  WebFrontend->>APIIndex: Send request with origin
  APIIndex->>BetterAuth: Dispatch to instance mapped to request origin
  BetterAuth-->>APIIndex: Return response
  APIIndex-->>WebFrontend: Return response with origin-specific CORS header
Loading

Merge Risk: ⚪ Minimal · up to 96702

The origin configuration now handles empty entries and canonical URLs correctly. Web requests and redirects use the current page origin while native behavior remains unchanged. The change is mergeable subject to normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 96702

Configured frontends gain access to the same authentication service. Origin allowlisting and cryptographic verification remain in place, and no introduced security vulnerability was established. Production routing, browser compatibility, and session continuity across hostnames remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Added origins join a common account-authentication trust domain, not an evidenced tenant-isolation boundary. Compromise of a configured frontend could expose users authenticated there to actions within their existing API privileges; origin-specific provider instances do not isolate their underlying account store.

Trust Boundaries and Controls

  • observed — CORS and CSRF use the same configured origins plus http://localhost:8081. Base/head comparison confirms the localhost exception already existed. Its production credential exposure was not established and is not treated as an introduced vulnerability.
  • observed — SIWE verification retains cryptographic ownership and challenge checks while adopting the selected origin hostname. WebAuthn retains expected challenge, credential identity, and RP ID checks alongside the expanded origin allowlist.

Resilience and Maintainability Implications

  • observed — Challenges retain random session identifiers, five-minute expiry, and atomic GETDEL consumption before verification, preventing concurrent reuse. Failed verification requires a fresh challenge. Credential persistence precedes cookie issuance and downstream side effects; partial completion remains possible, but this ordering and recovery limitation predate the PR.

Hardening Proposals

  • proposed — Treat adding an origin as granting authentication trust: restrict production entries to controlled HTTPS frontends and validate same-origin API routing, RP-domain discovery, browser compatibility, and cookie behavior during hostname cutovers.
🚥 Pre-merge checks | ✅ 3 | ❓ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check ❓ Inconclusive Issue #1341 has no acceptance criteria beyond checking whether a static build is sufficient for business frontend deployment. The PR implements and tests multiple frontend origins, including origin-aw… Provide the coding requirements or acceptance criteria for #1341, or explain how multiple-origin support establishes that a static build is sufficient for the business frontend deployment.
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding support for multiple frontend origins. The server scope is relevant, and the emoji does not prevent understanding.
Out of Scope Changes check ✅ Passed The changed server, client, authentication, redirect, CORS, WebAuthn, and test files support multiple frontend origins. The changesets document the server and mobile origin behavior. No unrelated chan…
Full details: Linked Issues check

Explanation

Issue #1341 has no acceptance criteria beyond checking whether a static build is sufficient for business frontend deployment. The PR implements and tests multiple frontend origins, including origin-aware authentication, CORS, redirects, cookies, and API requests. The available evidence does not establish that these changes answer the static-build question.

✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9f9457f515

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread server/utils/appOrigin.ts Outdated
Comment thread server/utils/appOrigin.ts Outdated
Comment thread src/utils/server.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0928fbeb-548e-4409-a55e-ae3fb6f79d45

📥 Commits

Reviewing files that changed from the base of the PR and between 48b2176 and 9f9457f.

📒 Files selected for processing (22)
  • .changeset/cool-baths-hide.md
  • .changeset/plenty-results-feel.md
  • server/api/auth/authentication.ts
  • server/api/auth/registration.ts
  • server/api/card.ts
  • server/api/index.ts
  • server/api/kyc.ts
  • server/index.ts
  • server/test/api/api.test.ts
  • server/test/api/auth.test.ts
  • server/test/e2e.ts
  • server/utils/appOrigin.ts
  • server/utils/auth.ts
  • server/utils/createCredential.ts
  • server/vitest.config.mts
  • src/components/add-funds/AddFunds.tsx
  • src/components/add-funds/Ramp.tsx
  • src/components/add-funds/Status.tsx
  • src/components/send-funds/SendFunds.tsx
  • src/utils/persona.ts
  • src/utils/server.ts
  • src/utils/useRampOnboarding.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread server/utils/appOrigin.ts Outdated
@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 80.55556% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 72.11%. Comparing base (e885fce) to head (a296c78).
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
server/api/auth/authentication.ts 66.66% 2 Missing ⚠️
server/api/auth/registration.ts 75.00% 0 Missing and 1 partial ⚠️
server/api/card.ts 75.00% 1 Missing ⚠️
server/api/index.ts 75.00% 1 Missing ⚠️
server/utils/appOrigin.ts 90.90% 0 Missing and 1 partial ⚠️
src/utils/persona.ts 0.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #1349      +/-   ##
==========================================
+ Coverage   71.29%   72.11%   +0.82%     
==========================================
  Files         303      304       +1     
  Lines       12858    12975     +117     
  Branches     4761     4828      +67     
==========================================
+ Hits         9167     9357     +190     
+ Misses       3450     3375      -75     
- Partials      241      243       +2     
Flag Coverage Δ
e2e 71.92% <80.55%> (+0.82%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f5785c51ce

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

version: "1",
issuedAt,
domain,
domain: new URL(origin(c.req.raw)).hostname,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve port numbers in SIWE domains

When a configured frontend uses a non-default port (explicitly retained by server/test/api/api.test.ts:64), this emits secondary.example as the SIWE domain while the URI is https://secondary.example:8443. A SIWE domain is the URI authority and includes the port, so strict clients or validators can reject the challenge and the later hostname-only checks reject standards-compliant messages. Use the URL's host rather than hostname consistently in the SIWE creation and validation paths.

Useful? React with 👍 / 👎.

This branch was successfully deployed

1 active deployment
test — f5785c51 Deployed Sep 30, 2026 by cruzdanilo via e2e #14460
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

app: check if static build is enough for business frontend deployment

2 participants