Karl Seguin
f70705b2ce
webapi: include Sec-Fetch-Site and Sec-Fetch-Mode headers
2026-09-18 12:34:19 +08:00
Muki Kiboigo
bf9ca09e33
dont dupe referer
2026-09-15 22:56:37 -07:00
Muki Kiboigo
afb98388cb
add referrer handling to CorsGate
2026-09-13 14:22:42 -07:00
Karl Seguin
66af1dc58d
webapi: Origin header + request header validation
...
Driven by a handful of /fetch/ WPT tests, three changes:
1 - Prevent libcurl from auto-inserting a 'application/x-www-form-urlencoded"
content type for types we really have no content-type for.
2 - Include origin header in all requests that should have it. This is something
CorsGate was doing in most cases, but cors can be disabled, so the logic
is now moved to HttpClient.
3 - Expands on the header guard added in https://github.com/lightpanda-io/browser/pull/3374/
Adds more modes and more header check. Request.init also uses the header
guard now
2026-09-09 14:44:48 +08:00
Karl Seguin
a5e27869d3
chore: remove unused imports
2026-09-05 17:51:47 +08:00
Muki Kiboigo
34b743fbd6
origin is tainted on cross origin redirects
2026-09-04 07:02:01 -07:00
Muki Kiboigo
1f9342e92f
add credentials to preflight key for cors
2026-09-04 07:00:02 -07:00
Muki Kiboigo
868882b0c8
add origin conditionally on no_cors
2026-09-04 07:00:02 -07:00
Muki Kiboigo
8a8bb3814f
fix test running
2026-09-04 07:00:01 -07:00
Muki Kiboigo
addba12426
add CORS metrics
2026-09-04 07:00:01 -07:00
Muki Kiboigo
12ed38dfdd
better no cors opaque behavior
2026-09-04 07:00:00 -07:00
Muki Kiboigo
d1f4605459
non-default credentials and request mode
2026-09-04 07:00:00 -07:00
Muki Kiboigo
b0fffe693a
more comprehensive cors singleflight key
2026-09-04 06:59:40 -07:00
Muki Kiboigo
2b06583662
authorization header doesnt accept wildcard
2026-09-04 06:59:40 -07:00
Muki Kiboigo
8ee714418d
proper safelist checking for CORS headers
2026-09-04 06:59:40 -07:00
Muki Kiboigo
89df63e956
safelisted methods always pass in CORS
2026-09-04 06:59:39 -07:00
Muki Kiboigo
c16a3b3585
fix warn log on preflight blocked
2026-09-04 06:59:39 -07:00
Muki Kiboigo
da00a90c02
set cors cross origin on transfer after no-cors check
2026-09-04 06:59:39 -07:00
Muki Kiboigo
d3c0291bd1
add request mode for Fetch
2026-09-04 06:59:39 -07:00
Muki Kiboigo
ddfa034310
add credentials_mode for proper CORS credentials handling
2026-09-04 06:59:39 -07:00
Muki Kiboigo
f31b32ac4e
don't store network in CorsGate
2026-09-04 06:59:38 -07:00
Muki Kiboigo
cf37a94f16
get rid of blocked on CorsGate check result
2026-09-04 06:59:38 -07:00
Muki Kiboigo
b976894315
properly hook up single flight for CorsGate
2026-09-04 06:59:38 -07:00
Muki Kiboigo
977874ce5f
initial preflighting
2026-09-04 06:59:38 -07:00
Muki Kiboigo
f428dc8e52
add origin header in CorsGate on cross origin
2026-09-04 06:59:38 -07:00
Muki Kiboigo
4e79f24814
basic validation without preflighting
2026-09-04 06:59:38 -07:00
Muki Kiboigo
212c806be5
add basic CorsGate scaffold
2026-09-04 06:59:37 -07:00