Skip to content

[pull] main from withastro:main#421

Merged
pull[bot] merged 3 commits intocode:mainfrom
withastro:main
Mar 4, 2026
Merged

[pull] main from withastro:main#421
pull[bot] merged 3 commits intocode:mainfrom
withastro:main

Conversation

@pull
Copy link

@pull pull bot commented Mar 4, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

astrobot-houston and others added 3 commits March 4, 2026 10:10
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…the internal base middleware (#15414)

Co-authored-by: ematipico <estoppa@cloudflare.com>
* Harden dev server with Sec-Fetch metadata validation

* Address review feedback: use logger, drop type casts, support allowedDomains

- Remove explicit 'as string | undefined' casts on req.headers access
- Log a warning via logger.warn() when blocking cross-origin requests
- Allow cross-origin requests from origins matching security.allowedDomains,
  using BaseApp.validateForwardedHost, to support proxied dev server setups
- Add tests for allowedDomains support

---------

Co-authored-by: bugbot <bugbot@users.noreply.github.com>
@pull pull bot locked and limited conversation to collaborators Mar 4, 2026
@pull pull bot added the ⤵️ pull label Mar 4, 2026
@pull pull bot merged commit b6c64d1 into code:main Mar 4, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants