HelloZeroNet / HelloZeroNet/ZeroNet

Access-Control-Allow-Origin not added with transparent proxy requests

Aperta
#1,452 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
JavaScript
Stelle
18.8k
Fork
2.3k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

## Description

So I've been testing the new [transparent proxy](https://github.com/HelloZeroNet/ZeroNet/pull/1445) feature, and it's quite cool to just be able to type `zerolstn.bit` into the address bar and have it resolve appropriately. The only issue is that the font files don't seem to have the 'Access-Control-Allow-Origin' header included in the response. However, when using http://127.0.0.1/zerolstn.bit the header is included and the font files do load.

## How to Reproduce

1. Run ZeroNet on port 80 with a transparent proxy:

```
sudo python ./zeronet.py --ui_port 80 --ui_trans_proxy
```

2. Change your `/etc/hosts` file to have localhost assigned to `zerolstn.bit`:

```
127.0.0.1 zerolstn.bit
```

3. Visit `zerolstn.bit` in your browser and see things load! But not the font files...

## Cause

This little line here seems to be the issue:

https://github.com/HelloZeroNet/ZeroNet/blob/7bff5f562c42a4a5f73e104c0f767c1413064aa6/src/Ui/UiRequest.py#L222-L223

Along with the code for `isSameOrigin`:

https://github.com/HelloZeroNet/ZeroNet/blob/7bff5f562c42a4a5f73e104c0f767c1413064aa6/src/Ui/UiRequest.py#L431-L436

`self.isSameOrigin` is returning false for the `zerolstn.bit` address. I believe it is due to there being no `127.0.0.1:43110` in front of the site URL, so we may need to change some regex here.

Tagging @JeremyRand for his interest.

Thanks!

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.