Skip to content

feat(local-proxy): forward browser-facing origin - #70

Closed
swarnava wants to merge 1 commit into
mainfrom
swarnava/local-proxy-origin-header
Closed

swarnava wants to merge 1 commit into
mainfrom
swarnava/local-proxy-origin-header

Conversation

@swarnava

@swarnava swarnava commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Send the resolved local proxy origin in the proxy-owned request header for local HTTP targets, HTTPS fallback deployments, and WebSocket upgrades. This gives fallback applications a stable origin that is not overwritten with x-forwarded-host at the Vercel edge.

Send the resolved local proxy origin in the proxy-owned request header for local HTTP targets, HTTPS fallback deployments, and WebSocket upgrades. This gives fallback applications a stable origin that is not overwritten with x-forwarded-host at the Vercel edge.

Replace any inbound copy of the header before forwarding fallback requests to prevent spoofed values from winning. Document the contract, add release metadata, and cover configured and default origins in tests.
@vercel

vercel Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Your Vercel team microfrontends-vtest314 is not permitted to deploy from this git repository. Contact an administrator to add github organization vercel as a Protected Git Scope in microfrontends-vtest314 on Vercel. Once added, commit again to see your changes.

Learn more: https://vercel.com/docs/security/protected-git-scopes

@swarnava swarnava closed this Sep 25, 2026
@swarnava
swarnava deleted the swarnava/local-proxy-origin-header branch September 25, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant