Skip to content

Add browser-safe hosted API access#3

Merged
t3chn merged 2 commits intomainfrom
codex/hosted-cors
Mar 9, 2026
Merged

Add browser-safe hosted API access#3
t3chn merged 2 commits intomainfrom
codex/hosted-cors

Conversation

@t3chn
Copy link
Copy Markdown
Contributor

@t3chn t3chn commented Mar 9, 2026

Summary

  • add REST CORS handling for browser clients on /v1/events and /v1/digests
  • add browser-safe WebSocket auth via Sec-WebSocket-Protocol bearer transport
  • align env/docs/tests around SIFTD_ALLOWED_ORIGINS with legacy fallback support

Issue ID

  • N/A

Test Plan

  • go test ./internal/hosted ./cmd/siftd

@t3chn t3chn merged commit 468d7c6 into main Mar 9, 2026
2 checks passed
@t3chn t3chn deleted the codex/hosted-cors branch March 9, 2026 09:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant