HelloZeroNet / HelloZeroNet/ZeroNet

Access-Control-Allow-Origin not added with transparent proxy requests

Ouverte
#1,452 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
JavaScript
Étoiles
18.8k
Forks
2.3k
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

## Description

So I've been testing the new [transparent proxy](https://github.com/HelloZeroNet/ZeroNet/pull/1445) feature, and it's quite cool to just be able to type `zerolstn.bit` into the address bar and have it resolve appropriately. The only issue is that the font files don't seem to have the 'Access-Control-Allow-Origin' header included in the response. However, when using http://127.0.0.1/zerolstn.bit the header is included and the font files do load.

## How to Reproduce

1. Run ZeroNet on port 80 with a transparent proxy:

```
sudo python ./zeronet.py --ui_port 80 --ui_trans_proxy
```

2. Change your `/etc/hosts` file to have localhost assigned to `zerolstn.bit`:

```
127.0.0.1 zerolstn.bit
```

3. Visit `zerolstn.bit` in your browser and see things load! But not the font files...

## Cause

This little line here seems to be the issue:

https://github.com/HelloZeroNet/ZeroNet/blob/7bff5f562c42a4a5f73e104c0f767c1413064aa6/src/Ui/UiRequest.py#L222-L223

Along with the code for `isSameOrigin`:

https://github.com/HelloZeroNet/ZeroNet/blob/7bff5f562c42a4a5f73e104c0f767c1413064aa6/src/Ui/UiRequest.py#L431-L436

`self.isSameOrigin` is returning false for the `zerolstn.bit` address. I believe it is due to there being no `127.0.0.1:43110` in front of the site URL, so we may need to change some regex here.

Tagging @JeremyRand for his interest.

Thanks!

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

Start in src/Ui/UiRequest.py at the linked lines around the Access-Control-Allow-Origin response handling and isSameOrigin. Reproduce the transparent proxy setup with --ui_port 80 and --ui_trans_proxy, using zerolstn.bit in /etc/hosts, then compare the header behavior with http://127.0.0.1/zerolstn.bit. Done means font responses through the transparent proxy include the expected header.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
networking
Type d'issue
Bug
Difficulté
3/5
Temps estimé
1-2 jours
Activité
À l'abandon
Clarté
Clairement spécifiée
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.