Skip to content

Allow cross-origin reads of public v2 responses - #63

Closed
vasilyevstan wants to merge 1 commit into
adsblol:mainfrom
vasilyevstan:cors-v2-responses
Closed

vasilyevstan wants to merge 1 commit into
adsblol:mainfrom
vasilyevstan:cors-v2-responses

Conversation

@vasilyevstan

Copy link
Copy Markdown

Why

The public /v2 API can be called successfully from a normal browser network, but browser JavaScript cannot read the response because it does not include Access-Control-Allow-Origin.

This blocks a direct-browser integration for LiveTrafficStan. Its current Cloudflare Worker path receives HTTP 429 from shared Cloudflare egress, while a normal browser/residential request can return HTTP 200. The production-access context and bounded request behavior are documented in adsblol/website#272.

What changes

  • add Access-Control-Allow-Origin: * to responses under the public /v2/ path;
  • leave every non-/v2 route unchanged;
  • add a regression proving a /v2 response is cross-origin readable while /docs is not given a CORS header.

The wildcard follows the existing public-route CORS convention in api_routes.py. It does not enable credentials, change authentication, modify rate limits, cache data, or add a proxy.

Important deployment boundary

This application middleware can cover responses generated by FastAPI. If nginx or another edge layer produces a 429 before FastAPI, that layer must add the same CORS header (and ideally Retry-After) for browser clients to read and honor the throttling response.

LiveTrafficStan sends at most one bounded point request every 20 seconds per eligible active tab, uses a maximum 54 NM radius, applies exponential 429 backoff up to five minutes, uses no-store, and displays ADSB.lol/ODbL attribution.

Validation

  • pytest tests/test_api.py::test_v2_responses_allow_cross_origin_reads -q — passed in Python 3.12
  • ruff check tests/test_api.py — passed
  • git diff --check — passed

The repository's full tests/test_api.py currently has unrelated pre-existing failures on main after the v2 route-factory refactor (the router registers no v2 routes, and stale tests still cover removed/moved paths). This PR intentionally does not expand into that separate issue.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants