✨ server: support multiple frontend origins - #1349
cruzdanilo wants to merge 1 commit into
Conversation
🦋 Changeset detectedLatest commit: f5785c5 The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Review skippedReview was skipped as selected files did not have any reviewable changes. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe server now supports multiple configured frontend origins for API routing, CORS, authentication, SIWE, and WebAuthn. Web API requests and provider redirect URLs use the current origin. ChangesMultiple Frontend Origins
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant WebFrontend
participant APIIndex
participant BetterAuth
WebFrontend->>APIIndex: Send request with origin
APIIndex->>BetterAuth: Dispatch to instance mapped to request origin
BetterAuth-->>APIIndex: Return response
APIIndex-->>WebFrontend: Return response with origin-specific CORS header
Merge Risk: ⚪ Minimal · up to The origin configuration now handles empty entries and canonical URLs correctly. Web requests and redirects use the current page origin while native behavior remains unchanged. The change is mergeable subject to normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Configured frontends gain access to the same authentication service. Origin allowlisting and cryptographic verification remain in place, and no introduced security vulnerability was established. Production routing, browser compatibility, and session continuity across hostnames remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 3 | ❓ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (3 passed)
Full details: Linked Issues checkExplanation Issue ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9f9457f515
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Advanced
Run ID: 0928fbeb-548e-4409-a55e-ae3fb6f79d45
📒 Files selected for processing (22)
.changeset/cool-baths-hide.md.changeset/plenty-results-feel.mdserver/api/auth/authentication.tsserver/api/auth/registration.tsserver/api/card.tsserver/api/index.tsserver/api/kyc.tsserver/index.tsserver/test/api/api.test.tsserver/test/api/auth.test.tsserver/test/e2e.tsserver/utils/appOrigin.tsserver/utils/auth.tsserver/utils/createCredential.tsserver/vitest.config.mtssrc/components/add-funds/AddFunds.tsxsrc/components/add-funds/Ramp.tsxsrc/components/add-funds/Status.tsxsrc/components/send-funds/SendFunds.tsxsrc/utils/persona.tssrc/utils/server.tssrc/utils/useRampOnboarding.ts
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #1349 +/- ##
==========================================
+ Coverage 71.29% 72.11% +0.82%
==========================================
Files 303 304 +1
Lines 12858 12975 +117
Branches 4761 4828 +67
==========================================
+ Hits 9167 9357 +190
+ Misses 3450 3375 -75
- Partials 241 243 +2
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5785c51ce
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| version: "1", | ||
| issuedAt, | ||
| domain, | ||
| domain: new URL(origin(c.req.raw)).hostname, |
There was a problem hiding this comment.
Preserve port numbers in SIWE domains
When a configured frontend uses a non-default port (explicitly retained by server/test/api/api.test.ts:64), this emits secondary.example as the SIWE domain while the URI is https://secondary.example:8443. A SIWE domain is the URI authority and includes the port, so strict clients or validators can reject the challenge and the later hostname-only checks reject standards-compliant messages. Use the URL's host rather than hostname consistently in the SIWE creation and validation paths.
Useful? React with 👍 / 👎.
closes #1341
Summary by CodeRabbit