Fix browser SDK CORS on ingest routes#154
Merged
Merged
Conversation
Dashboard allowlist still protects /api routes with credentials; ingest uses API key auth instead. Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
CORS_ORIGINS) applied to all routes, including/ingest/*Authorizationfrom customer domains, so preflight was rejected (404, noAccess-Control-Allow-Origin)/api/*keeps the dashboard allowlist with credentialsRoot cause
Code bug (not a Railway env misconfiguration). v1.4.3/v1.4.4 did not touch CORS; the restrictive global policy has been in place since
cors-config.tswas introduced. Production currently hasCORS_ORIGINS=https://telemetry-tracker.com(verified via curl), which is correct for the dashboard but blocks SDK traffic from instrumented apps.Test plan
pnpm --filter api test(cors-config + smoke OPTIONS tests)pnpm lint && pnpm buildcurl -X OPTIONS https://api.telemetry-tracker.com/ingest/event -H "Origin: https://example.com" -H "Access-Control-Request-Method: POST" -H "Access-Control-Request-Headers: authorization,content-type"→ 204 with reflected originRailway (no env change required for ingest fix)
Ensure API service has:
CORS_ORIGINS=https://telemetry-tracker.com(or comma-list if using www — see note below)TELEMETRY_DASHBOARD_ORIGIN=https://telemetry-tracker.comOptional: add
https://www.telemetry-tracker.comtoCORS_ORIGINSif users hit www (www currently 404s on dashboard — separate DNS/hosting issue).Made with Cursor