Skip to content

Honor changeOrigin for WebSocket upgrades - #979

Open
raashish1601 wants to merge 1 commit into
http-party:masterfrom
raashish1601:fix/websocket-origin-codex-b
Open

raashish1601 wants to merge 1 commit into
http-party:masterfrom
raashish1601:fix/websocket-origin-codex-b

Conversation

@raashish1601

Copy link
Copy Markdown

WebSocket upgrades still force changeOrigin: true, so proxyOptions.changeOrigin: false only affects normal HTTP requests. Remove the per-upgrade override so WebSockets inherit the same proxy configuration as HTTP. The default remains true.

Add real loopback WebSocket handshakes that check the Host received by the upstream server for default, explicitly enabled, and disabled changeOrigin.

Validation on Windows with Node 24.12.0:

  • New regression on unchanged source: 12 passed, 1 failed (the disabled case).
  • Fixed WebSocket suite: 13 passed.
  • npm test -- --jobs=1: 530 passed, 0 failed, 1 skipped.

An initial full run encountered a CLI socket hangup. The pristine CLI suite (40 assertions) and unchanged full rerun passed; no timeout or DNS configuration was changed.

Relevant issues

Fixes #965.

Contributor checklist
  • Provide tests for the changes (unless documentation-only)
  • Documented any new features, CLI switches, etc. (not applicable: existing option behavior)
    • Server --help output
    • README.md
    • doc/http-server.1 (use the same format as other entries)
  • The pull request is being made against the master branch

AI assistance: Codex assisted with investigation, implementation, and validation.

Maintainer checklist
  • Assign a version triage tag
  • Approve tests if applicable

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Configurable changeOrigin in websocket listener?

1 participant