fix(cors): split public and admin GraphQL origins#71
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Warning Review limit reached
More reviews will be available in 57 minutes and 55 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (15)
📝 WalkthroughWalkthroughThis PR splits CORS origin handling for GraphQL endpoints into two separate allowlists. Public GraphQL endpoints ( ChangesCORS Origin Split for GraphQL
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: debd085ace
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
84b580a to
786e390
Compare
Summary
ADMIN_ALLOWED_ORIGINSvaluesALLOWED_ORIGINSas a fallback and documentPUBLIC_ALLOWED_ORIGINS/ADMIN_ALLOWED_ORIGINSVerification
DATABASE_URL=sqlite::memory: go test -race ./...DATABASE_URL=sqlite::memory: go test ./...go build -v ./...make lint/graphqlworks from allowed and disallowed browser origins/admin/graphqlworks fromhttp://127.0.0.1:13000/admin/graphqlis browser-blocked fromhttp://127.0.0.1:13001Screenshots
Local verification screenshots were generated at:
/tmp/hyperindex-cors-test/screens/allowed-client-origin.png/tmp/hyperindex-cors-test/screens/disallowed-admin-origin.pngSummary by CodeRabbit
New Features
Configuration Changes
PUBLIC_ALLOWED_ORIGINS(defaults to*) andADMIN_ALLOWED_ORIGINS(requires explicit origins).ALLOWED_ORIGINSdeprecated but supported as fallback for admin origins.Documentation