Allow cross-origin reads of public v2 responses - #63
Closed
vasilyevstan wants to merge 1 commit into
Closed
vasilyevstan wants to merge 1 commit into
vasilyevstan wants to merge 1 commit into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The public
/v2API can be called successfully from a normal browser network, but browser JavaScript cannot read the response because it does not includeAccess-Control-Allow-Origin.This blocks a direct-browser integration for LiveTrafficStan. Its current Cloudflare Worker path receives HTTP 429 from shared Cloudflare egress, while a normal browser/residential request can return HTTP 200. The production-access context and bounded request behavior are documented in adsblol/website#272.
What changes
Access-Control-Allow-Origin: *to responses under the public/v2/path;/v2route unchanged;/v2response is cross-origin readable while/docsis not given a CORS header.The wildcard follows the existing public-route CORS convention in
api_routes.py. It does not enable credentials, change authentication, modify rate limits, cache data, or add a proxy.Important deployment boundary
This application middleware can cover responses generated by FastAPI. If nginx or another edge layer produces a 429 before FastAPI, that layer must add the same CORS header (and ideally
Retry-After) for browser clients to read and honor the throttling response.LiveTrafficStan sends at most one bounded point request every 20 seconds per eligible active tab, uses a maximum 54 NM radius, applies exponential 429 backoff up to five minutes, uses
no-store, and displays ADSB.lol/ODbL attribution.Validation
pytest tests/test_api.py::test_v2_responses_allow_cross_origin_reads -q— passed in Python 3.12ruff check tests/test_api.py— passedgit diff --check— passedThe repository's full
tests/test_api.pycurrently has unrelated pre-existing failures onmainafter the v2 route-factory refactor (the router registers no v2 routes, and stale tests still cover removed/moved paths). This PR intentionally does not expand into that separate issue.