HelloZeroNet / HelloZeroNet/ZeroNet

Access-Control-Allow-Origin not added with transparent proxy requests

Open
#1,452 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
18.8k
Forks
2.3k
PR merge metrics
No merged PRs in 30d

Description

## Description

So I've been testing the new [transparent proxy](https://github.com/HelloZeroNet/ZeroNet/pull/1445) feature, and it's quite cool to just be able to type `zerolstn.bit` into the address bar and have it resolve appropriately. The only issue is that the font files don't seem to have the 'Access-Control-Allow-Origin' header included in the response. However, when using http://127.0.0.1/zerolstn.bit the header is included and the font files do load.

## How to Reproduce

1. Run ZeroNet on port 80 with a transparent proxy:

```
sudo python ./zeronet.py --ui_port 80 --ui_trans_proxy
```

2. Change your `/etc/hosts` file to have localhost assigned to `zerolstn.bit`:

```
127.0.0.1 zerolstn.bit
```

3. Visit `zerolstn.bit` in your browser and see things load! But not the font files...

## Cause

This little line here seems to be the issue:

https://github.com/HelloZeroNet/ZeroNet/blob/7bff5f562c42a4a5f73e104c0f767c1413064aa6/src/Ui/UiRequest.py#L222-L223

Along with the code for `isSameOrigin`:

https://github.com/HelloZeroNet/ZeroNet/blob/7bff5f562c42a4a5f73e104c0f767c1413064aa6/src/Ui/UiRequest.py#L431-L436

`self.isSameOrigin` is returning false for the `zerolstn.bit` address. I believe it is due to there being no `127.0.0.1:43110` in front of the site URL, so we may need to change some regex here.

Tagging @JeremyRand for his interest.

Thanks!

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.