From b62040457d12841afdaedb6e9e74df31684519ea Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Wed, 22 Apr 2026 18:07:41 -0700 Subject: [PATCH] lith/Caddyfile: let Kubo's CORS header pass through unchanged The header_down -Access-Control-Allow-Origin strip fired but the followup set didn't re-add the header, leaving ipfs.aesthetic.computer with no CORS header at all. Kubo already emits a single * so the simplest fix is to remove both header_down directives and pass upstream through verbatim. Co-Authored-By: Claude Opus 4.7 (1M context) --- lith/Caddyfile | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/lith/Caddyfile b/lith/Caddyfile index aa776408e5..70f1e32691 100644 --- a/lith/Caddyfile +++ b/lith/Caddyfile @@ -133,14 +133,12 @@ } # --- ipfs.aesthetic.computer (self-hosted IPFS gateway) --- - # Kubo's gateway already emits Access-Control-Allow-Origin; strip upstream - # copies so Caddy owns exactly one, avoiding "*, *" dupes that browsers reject. + # Kubo's gateway already emits a single Access-Control-Allow-Origin: *, + # so we pass it through unmodified. An earlier Caddy-level `header` + # directive added a second copy, producing "*, *" which browsers reject. @ipfs host ipfs.aesthetic.computer handle @ipfs { - reverse_proxy localhost:8090 { - header_down -Access-Control-Allow-Origin - header_down Access-Control-Allow-Origin * - } + reverse_proxy localhost:8090 } # --- justanothersystem.org --- -- 2.51.2