Files
deepseek-harness/packages/host/apiproxy/README.i18n.yaml
T
creatixchu d2fea6d789 fix(apiproxy): refuse non-JSON media types on /api POST bodies
Browsers send "simple" POSTs (text/plain, form encodings) without a CORS
preflight, so a malicious page could execute side-effectful RPCs blind —
the response stays unreadable cross-origin, but session.prompt would
still run. The carrier now answers 415 unless the declared media type is
application/json, forcing every cross-site attempt into a preflight this
server never answers. Raw-fetch specs gain the header; a new handler case
proves the fence rejects before the impl runs.
2026-07-28 14:40:13 +08:00

7 lines
432 B
YAML

# Bilingual-pair consistency record (docs/i18n/README.md): the git blob hash of each
# side as of the last confirmed-consistent state. Both languages carry equal authority;
# after editing either side, bring the other along and re-record with:
# pnpm run verify-translation-pairing --write packages/host/apiproxy/README.md
README.md: 63294100cd0dc62f9822a3ca9678c1034880169f
README.zh.md: 251b4b0356da5f1fb518d133a92f484da957b951