Skip to content

Fix origin rejection when connecting Link - #151

Merged
fmhall merged 1 commit into
mainfrom
mason/fix-link-form-origin
Oct 2, 2026
Merged

fmhall merged 1 commit into
mainfrom
mason/fix-link-form-origin

Conversation

@fmhall

@fmhall fmhall commented Oct 2, 2026

Copy link
Copy Markdown
Member

The Link page used no-referrer, which makes browsers send Origin: null on native form POSTs. Clicking Connect Link therefore hit the endpoint's origin check and returned “Invalid request origin.”

Use same-origin for the page so its connect/disconnect forms retain the Origin header. The endpoint still rejects foreign, missing, and null origins, and its redirect to Link retains Referrer-Policy: no-referrer.

Validation:

  • Real browser form test reproduced Origin: null before the change and the correct origin afterward; the cross-origin redirect sent no Referer.
  • pnpm check passed: 773 tests, lint, types, formatting, and Knip. The Link integration test covers rejected origins and the OAuth redirect policy.
  • DATABASE_URL=postgresql://postgres:postgres@127.0.0.1:54329/open_instinct KERNEL_API_KEY=build-only BETTER_AUTH_URL=http://localhost:3000 pnpm build passed.
  • Independent read-only review found no actionable issues.

Live wallet authorization has not been completed. No environment variable values are included in this change.

@fmhall
fmhall marked this pull request as ready for review October 2, 2026 16:29
@fmhall
fmhall merged commit dd82dd9 into main Oct 2, 2026
2 checks passed

This branch was successfully deployed

1 active deployment
Preview — dd946d17 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant