Skip to content

fix: return opaque responses from file and http protocol handlers for cross-origin no-cors requests - #52853

Merged
MarshallOfSound merged 1 commit into
43-x-yfrom
trop/43-x-y-bp-fix-return-opaque-responses-from-file-and-http-protocol-handlers-for-cross-origin-no-cors-requests-1786877752394
Aug 16, 2026
Merged

MarshallOfSound merged 1 commit into
43-x-yfrom
trop/43-x-y-bp-fix-return-opaque-responses-from-file-and-http-protocol-handlers-for-cross-origin-no-cors-requests-1786877752394

Conversation

@trop

@trop trop Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Backport of #52822

See that PR for details.

Notes: Fixed registerFileProtocol and registerHttpProtocol returning readable responses to cross-origin no-cors fetches; they now return opaque responses like protocol.handle.

… cross-origin no-cors requests

The opaque tagging added for cross-origin no-cors loads is written to a
local response head that only the string/buffer/stream sinks deliver. The
file sink (asar/file loader) and the http sink (URLPipeLoader) build or
forward their own response head, dropping the tag, so a cross-origin
mode=no-cors fetch of a registerFileProtocol or registerHttpProtocol
resource was delivered as a basic, script-readable response.

Compute the opaque decision once in StartLoading and interpose a
URLLoaderClient on the file and http sinks that re-applies the opaque tag to
the head those sinks emit, matching the behaviour of the other sinks.

Co-authored-by: Sam Attard <[email protected]>
@trop
trop Bot requested a review from MarshallOfSound August 16, 2026 10:56
@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) August 16, 2026 10:56
@trop trop Bot added 43-x-y backport This is a backport PR semver/patch backwards-compatible bug fixes labels Aug 16, 2026
@MarshallOfSound
MarshallOfSound merged commit 80178e4 into 43-x-y Aug 16, 2026
96 checks passed
@MarshallOfSound
MarshallOfSound deleted the trop/43-x-y-bp-fix-return-opaque-responses-from-file-and-http-protocol-handlers-for-cross-origin-no-cors-requests-1786877752394 branch August 16, 2026 13:15
@release-clerk

release-clerk Bot commented Aug 16, 2026

Copy link
Copy Markdown

Release Notes Persisted

Fixed registerFileProtocol and registerHttpProtocol returning readable responses to cross-origin no-cors fetches; they now return opaque responses like protocol.handle.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

43-x-y backport This is a backport PR semver/patch backwards-compatible bug fixes

Projects

No open projects
Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant