feat(selfhost): allow additional trusted browser origins - #1441
Merged
RhysSullivan merged 4 commits intoAug 28, 2026
Merged
Conversation
Author
|
Some context on why the mixed-protocol example (https canonical + http trusted origins) is the headline use case: umbrelOS — and home servers like it — serve local access ( |
The Secure-cookie warning fired whenever any trusted origin was http, which includes the plain http://localhost default, so every local boot printed it. Warn only for the mixed case an operator opts into: an http alias alongside an https canonical URL, where the canonical origin really does lose Secure cookies. Move the resolver below loadConfig with the other env knobs and state why each rejected origin shape is refused rather than trimmed. Cover the rejected shapes as a table, plus the blank-list and bare-hostname cases.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1440
Summary
EXECUTOR_TRUSTED_ORIGINSallowlist for self-hosted browser aliasesEXECUTOR_WEB_BASE_URLcanonical for OAuth callbacks and generated URLsSecurity
Verification
bun run formatbun run format:checkbun run lintbun run typecheckbun run --cwd apps/host-selfhost test(18 files, 80 tests)