From 5beafaf5ba6decc1838f4394ff5ff2b4a751be69 Mon Sep 17 00:00:00 2001 From: Kieran Klukas Date: Sun, 24 May 2026 01:48:41 -0400 Subject: [PATCH] chore: update proxy --- web/src/lib/proxy.ts | 33 ++++++++++++++++++--------------- 1 file changed, 18 insertions(+), 15 deletions(-) diff --git a/web/src/lib/proxy.ts b/web/src/lib/proxy.ts index 5436abf..50856d0 100644 --- a/web/src/lib/proxy.ts +++ b/web/src/lib/proxy.ts @@ -1,15 +1,3 @@ -/** - * Shared backend proxy. - * - * Both /api/* and /auth/* are owned by the Go backend. The Cloudflare - * Worker (or Vite in dev) takes the inbound request, swaps in BACKEND_URL, - * and forwards it verbatim. No auth, no rewriting, no caching. All real - * work happens upstream. - * - * Streaming is preserved because we hand the original body and - * ReadableStream straight through. - */ - import type { RequestHandler } from '@sveltejs/kit'; export function backendProxy(): RequestHandler { @@ -17,16 +5,31 @@ export function backendProxy(): RequestHandler { const backend = platform?.env?.BACKEND_URL ?? 'http://localhost:8080'; const target = new URL(url.pathname + url.search, backend); + // Build clean headers — forward everything except host and cf-* headers + const headers = new Headers(); + for (const [key, value] of request.headers) { + // Skip hop-by-hop and Cloudflare-internal headers + if (key.startsWith('cf-') || key === 'host' || key === 'x-forwarded-host') { + continue; + } + headers.set(key, value); + } + // Set the correct host for the upstream backend + headers.set('Host', target.host); + // Let the backend know the original protocol and host + headers.set('X-Forwarded-Host', url.host); + headers.set('X-Forwarded-Proto', url.protocol.replace(':', '')); + const init: RequestInit = { method: request.method, - headers: request.headers, + headers, body: request.method === 'GET' || request.method === 'HEAD' ? undefined - : (request.body as never), + : request.body, redirect: 'manual' }; - // Streaming bodies need duplex on fetch(). + // Streaming bodies need duplex on fetch() if (init.body) (init as { duplex?: string }).duplex = 'half'; return fetch(target, init); -- 2.51.2