From e48cb5ee1a68dd8ed5b3187d8ebfe22670058e10 Mon Sep 17 00:00:00 2001 From: Enrico Graziani <14198729+erikologic@users.noreply.github.com> Date: Sun, 1 Mar 2026 21:25:27 +0000 Subject: [PATCH] Fix CORS: reflect request headers instead of wildcard Firefox rejects credentialed cross-origin requests when Access-Control-Allow-Headers is `*`, because per the Fetch spec the wildcard is not treated as a wildcard when credentials are involved. This causes failures on endpoints like getSession and createSession when accessed from bsky.app. Switch from `.allow_headers(Any)` to `.allow_headers(AllowHeaders::mirror_request())` which echoes the browser's Access-Control-Request-Headers back verbatim, matching the behaviour of the PDS's Express cors middleware. Co-Authored-By: Claude Opus 4.6 --- src/main.rs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/main.rs b/src/main.rs index c91cf22..168b92f 100644 --- a/src/main.rs +++ b/src/main.rs @@ -33,7 +33,7 @@ use tower_governor::{ }; use tower_http::{ compression::CompressionLayer, - cors::{Any, CorsLayer}, + cors::{AllowHeaders, Any, CorsLayer}, }; use tracing::log; use tracing_subscriber::{EnvFilter, fmt, prelude::*}; @@ -352,7 +352,7 @@ async fn main() -> Result<(), Box> { let cors = CorsLayer::new() .allow_origin(Any) .allow_methods([Method::GET, Method::OPTIONS, Method::POST]) - .allow_headers(Any); + .allow_headers(AllowHeaders::mirror_request()); let mut app = Router::new() .route("/", get(root_handler)) -- 2.51.2